Vulnerability Description
PHParanoid before 0.4 does not properly restrict access to the members area by unauthenticated users, which has unknown impact and remote attack vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phparanoid | Phparanoid | <= 0.3 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/28847Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=575358PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40516
- http://secunia.com/advisories/28847Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=575358PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40516
FAQ
What is CVE-2008-5673?
CVE-2008-5673 is a vulnerability with a CVSS score of 6.5 (MEDIUM). PHParanoid before 0.4 does not properly restrict access to the members area by unauthenticated users, which has unknown impact and remote attack vectors.
How severe is CVE-2008-5673?
CVE-2008-5673 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5673?
Check the references section above for vendor advisories and patch information. Affected products include: Phparanoid Phparanoid.