CVE-2008-5708 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.64% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-12-24 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| slimcms | slimcms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SlimCMS 1.0.0 - 'redirect.php' Privilege Escalation | 2008-10-10 |
References
- http://securityreason.com/securityalert/4804
- http://www.securityfocus.com/bid/31736
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45824
- https://www.exploit-db.com/exploits/6729
- http://securityreason.com/securityalert/4804
- http://www.securityfocus.com/bid/31736
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45824
- https://www.exploit-db.com/exploits/6729
→ the Explorer · watch your stack · NVD