CVE-2008-6752 Vulnerability Details

  /     /     /  

CVE-2008-6752 Metadata Quick Info

CVE Published: 24/04/2009 | CVE Updated: 07/08/2024 | CVE Year: 2008
Source: mitre | Vendor: n/a | Product: n/a
Status : PUBLISHED

CVE-2008-6752 Description

adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator\'s password and gain privileges via a direct request with modified newpass1 and newpass2 parameters in a Change operation.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: n/a
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).