CVE-2008-5221 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 85)
Patch early
A public exploit exists.
Description
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.55% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-11-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| wportfolio | wportfolio |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | wPortfolio 0.3 - Admin Password Changing | 2008-11-20 |
References
- http://securityreason.com/securityalert/4631
- http://www.securityfocus.com/bid/32384
- http://www.vupen.com/english/advisories/2008/3219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46772
- https://www.exploit-db.com/exploits/7170
- http://securityreason.com/securityalert/4631
- http://www.securityfocus.com/bid/32384
- http://www.vupen.com/english/advisories/2008/3219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46772
- https://www.exploit-db.com/exploits/7170
→ the Explorer · watch your stack · NVD