peter bassill · operator
$ cve CVE-2008-1971 JSON

CVE-2008-1971 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.21% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2008-04-27
Last modified2026-06-16

Affected (1)

VendorProduct
phphqphshoutbox final

Public exploits

SourceTitleDate
exploit-dbPhShoutBox 1.5 - Insecure Cookie Handling2008-04-18

References

→ the Explorer  ·  watch your stack  ·  NVD