Vulnerability CVE-2008-5221


Published: 2008-11-25   Modified: 2012-02-12

Description:
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.

See advisories in our WLB2 database:
Topic
Author
Date
High
wPortfolio <= 0.3 Admin Password Changing Exploit
G4N0K
26.11.2008

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Wportfolio -> Wportfolio 

 References:
http://xforce.iss.net/xforce/xfdb/46772
http://www.vupen.com/english/advisories/2008/3219
http://www.securityfocus.com/bid/32384
http://www.milw0rm.com/exploits/7170
http://securityreason.com/securityalert/4631

Copyright 2024, cxsecurity.com

 

Back to Top