PT-2008-1910 · Eticket · Eticket

Published

2008-01-15

·

Updated

2018-10-15

·

CVE-2008-0266

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions eTicket version 1.5.5.2
Description A cross-site request forgery (CSRF) issue in the admin.php file allows remote attackers to change the administrative password and possibly perform other administrative tasks, provided they either know the old password or can leverage a separate SQL injection vulnerability.
Recommendations For eTicket version 1.5.5.2, as a temporary workaround, consider restricting access to the admin.php file until a patch is available. Additionally, ensure that the old password is not known to unauthorized parties and mitigate the risk of SQL injection vulnerabilities to prevent leverage by attackers.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0266

Affected Products

Eticket