Vulnerability Description
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Creloaded | Cre Loaded | <= 6.2 |
Related Weaknesses (CWE)
References
- http://hosting-4-creloaded.com/node/116ExploitURL Repurposed
- http://hosting-4-creloaded.com/node/116ExploitURL Repurposed
FAQ
What is CVE-2009-5077?
CVE-2009-5077 is a vulnerability with a CVSS score of 7.5 (HIGH). CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) in...
How severe is CVE-2009-5077?
CVE-2009-5077 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-5077?
Check the references section above for vendor advisories and patch information. Affected products include: Creloaded Cre Loaded.