Vulnerability Details CVE-2008-6772
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a new account with the username of a target user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 82.9%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2008-6772
-
cpe:2.3:a:peterselie:yourplace:*
-
cpe:2.3:a:peterselie:yourplace:1.0
-
cpe:2.3:a:peterselie:yourplace:1.0.1