CVE-2007-4338
Published Aug 14, 2007
Last updated 6 years ago
Overview
- Description
- index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:haudenschilt:family_connections_cms:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7404352F-25A7-472A-BE0C-F4B35EE29E9C", "versionEndIncluding": "0.8" }, { "criteria": "cpe:2.3:a:haudenschilt:family_connections_cms:0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A3DC010-D142-4DEB-B425-04B8E10D9AEB" }, { "criteria": "cpe:2.3:a:haudenschilt:family_connections_cms:0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "505E59AC-08C9-4D13-8470-76191D73F6A8" }, { "criteria": "cpe:2.3:a:haudenschilt:family_connections_cms:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBA041C5-5FF4-46A8-9F1D-74025E742EAA" }, { "criteria": "cpe:2.3:a:haudenschilt:family_connections_cms:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D025AEE2-75AF-4959-9E78-E9AB6E163664" } ], "operator": "OR" } ] } ]