admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.
References
Configurations
History
21 Nov 2024, 00:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://ezcms.eztechhelp.com/index.php?page=3&nid=27 - Patch | |
References | () http://www.securityfocus.com/bid/29738 - Exploit, Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/43091 - | |
References | () https://www.exploit-db.com/exploits/5819 - |
Information
Published : 2008-06-30 18:24
Updated : 2024-11-21 00:48
NVD link : CVE-2008-2920
Mitre link : CVE-2008-2920
CVE.ORG link : CVE-2008-2920
JSON object : View
Products Affected
ezcms
- eztechhelp_ezcms
CWE
CWE-287
Improper Authentication