Vulnerability CVE-2008-5219


Published: 2008-11-25   Modified: 2012-02-12

Description:
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.

See advisories in our WLB2 database:
Topic
Author
Date
High
VideoScript <= 4.0.1.50 Admin Change Password Exploit
G4N0K
26.11.2008

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Videoscript -> Videoscript 

 References:
http://www.milw0rm.com/exploits/7149
http://securityreason.com/securityalert/4634
http://secunia.com/advisories/32718
http://osvdb.org/49885

Copyright 2024, cxsecurity.com

 

Back to Top