CVE-2008-2682 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.53% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-06-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| realm project | realm cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | realm CMS 2.3 - Multiple Vulnerabilities | 2008-06-09 |
References
- http://bugreport.ir/index.php?/40
- http://secunia.com/advisories/30583
- http://www.securityfocus.com/bid/29616
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42960
- https://www.exploit-db.com/exploits/5766
- http://bugreport.ir/index.php?/40
- http://secunia.com/advisories/30583
- http://www.securityfocus.com/bid/29616
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42960
- https://www.exploit-db.com/exploits/5766
→ the Explorer · watch your stack · NVD