Vulnerability Description
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blogator-Script | Blogator-Script | 0.95 |
Related Weaknesses (CWE)
References
- http://osvdb.org/51227
- http://www.securityfocus.com/archive/1/490501/100/0/threaded
- https://www.exploit-db.com/exploits/5370
- http://osvdb.org/51227
- http://www.securityfocus.com/archive/1/490501/100/0/threaded
- https://www.exploit-db.com/exploits/5370
FAQ
What is CVE-2008-6473?
CVE-2008-6473 is a vulnerability with a CVSS score of 6.4 (MEDIUM). _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.
How severe is CVE-2008-6473?
CVE-2008-6473 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6473?
Check the references section above for vendor advisories and patch information. Affected products include: Blogator-Script Blogator-Script.