Vulnerability Description
Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Online-Bookmarks | Web Based Bookmark Application | 0.4 |
References
- http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&release_id=174401
- http://secunia.com/advisories/12728/PatchVendor Advisory
- http://www.securityfocus.com/bid/11305Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17602
- http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&release_id=174401
- http://secunia.com/advisories/12728/PatchVendor Advisory
- http://www.securityfocus.com/bid/11305Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17602
FAQ
What is CVE-2004-2155?
CVE-2004-2155 is a vulnerability with a CVSS score of 7.5 (HIGH). Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6)...
How severe is CVE-2004-2155?
CVE-2004-2155 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2155?
Check the references section above for vendor advisories and patch information. Affected products include: Online-Bookmarks Web Based Bookmark Application.