peter bassill · operator
$ cve CVE-2008-6231 JSON

CVE-2008-6231 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.91% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-255
On CISA KEVno
Public exploityes
Published2009-02-20
Last modified2026-06-16

Affected (1)

VendorProduct
preprojectspre classified listings

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD