PT-2008-1890 · Unknown · Uploadscript

Dj7Xpl

·

Published

2008-01-12

·

Updated

2017-09-29

·

CVE-2008-0246

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions UploadScript version 1.0
Description The issue allows remote attackers to gain administrator privileges due to a lack of original password verification when changing to a new password. This is achieved via the pass parameter in a 'nopass' (Set Password) action.
Recommendations For UploadScript version 1.0, consider disabling the password change functionality until a patch is available to enforce original password checks before allowing changes to a new password. Restrict access to the admin.php script to minimize the risk of exploitation. Avoid using the pass parameter in the 'nopass' action for the time being.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0246

Affected Products

Uploadscript