Vulnerability Description
NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.
CVSS Score
10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Newsphp | Newsphp | All versions |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2004-04/0161.html
- http://secunia.com/advisories/11346Vendor Advisory
- http://securitytracker.com/alerts/2004/Apr/1009740.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15836
- http://archives.neohapsis.com/archives/bugtraq/2004-04/0161.html
- http://secunia.com/advisories/11346Vendor Advisory
- http://securitytracker.com/alerts/2004/Apr/1009740.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15836
FAQ
What is CVE-2004-2689?
CVE-2004-2689 is a vulnerability with a CVSS score of 10.0 (HIGH). NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.
How severe is CVE-2004-2689?
CVE-2004-2689 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2689?
Check the references section above for vendor advisories and patch information. Affected products include: Newsphp Newsphp.