CVE-2008-6743
Last modified
CVE-2008-6743 is a vulnerability of currently unknown severity. RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.
Description
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Shock-Therapy | Rsmscript | 1.21 |
References
- http://osvdb.org/50802Exploit
- http://secunia.com/advisories/33150Vendor Advisory
- http://osvdb.org/50802Exploit
- http://secunia.com/advisories/33150Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-6743?
How severe is CVE-2008-6743?
How do I fix CVE-2008-6743?
Are you affected by CVE-2008-6743?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
