peter bassill · operator
$ cve CVE-2008-5219 JSON

CVE-2008-5219 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS6.85% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2008-11-25
Last modified2026-06-16

Affected (1)

VendorProduct
videoscriptvideoscript

Public exploits

SourceTitleDate
exploit-dbVideoScript 4.0.1.50 - Change Admin Password2008-11-17

References

→ the Explorer  ·  watch your stack  ·  NVD