peter bassill · operator
$ cve CVE-2013-6492 JSON

CVE-2013-6492 EXPLOIT

5.8
MEDIUM · CVSS 2.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.

Scoring

CVSS5.8 (MEDIUM, v2.0)
VectorAV:A/AC:L/Au:N/C:P/I:P/A:P
EPSS4% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2014-02-14
Last modified2026-06-17

Affected (1)

VendorProduct
ryan oharapiranha

Public exploits

SourceTitleDate
exploit-dbRedHat Piranha - Remote Security Bypass2013-12-11

References

→ the Explorer  ·  watch your stack  ·  NVD