peter bassill · operator
$ cve CVE-2008-5708 JSON

CVE-2008-5708 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.64% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2008-12-24
Last modified2026-06-16

Affected (1)

VendorProduct
slimcmsslimcms

Public exploits

SourceTitleDate
exploit-dbSlimCMS 1.0.0 - 'redirect.php' Privilege Escalation2008-10-10

References

→ the Explorer  ·  watch your stack  ·  NVD