Vulnerability Details CVE-2009-1780
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.022
EPSS Ranking 83.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2009-1780
-
cpe:2.3:a:frax:php_recommend:-
-
cpe:2.3:a:frax:php_recommend:1.3