Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-6523

EPSS 1.77% · P83
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-6523

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
openInvoice 'auth.php'身份认证授权绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
openInvoice是一个发票管理小工具,可以根据格式要求定制和打印,并通过邮件自动发送给发票被开具者。 openInvoice0.90 beta版本及其早期版本的auth.php允许远程攻击者通过设置oiauth cookie,绕过权限并获得特权。注意:该漏洞可以与resetpass.php中的一个独立漏洞结合,更改任意用户的密码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-6523

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-6523

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-03-25 · 58 CVEs total

CVE-2009-1076Sun Java System Identity Manager 用户登录功能信息泄露漏洞
CVE-2009-0891IBM WebSphere Application Server Username Token Option 会话劫持漏洞
CVE-2009-0928Adobe Acrobat和Reader JBIG2图形处理堆溢出漏洞
CVE-2009-0921HP OpenView网络节点管理器Accept-Language HTTP头堆溢出漏洞
CVE-2009-0920HP OpenView网络节点管理器OvAcceptLang参数堆溢出漏洞
CVE-2009-1061Adobe Acrobat Reader JBIG2未明向量代码执行漏洞
CVE-2009-1080Sun Java System Identity Manager多个跨站脚本漏洞
CVE-2009-1079Sun Java System Identity Manager多个跨站脚本漏洞
CVE-2009-1078Sun Java System Identity Manager 权限分配多个未明安全漏洞
CVE-2009-1077Sun Java System Identity Manager 更改口令工具访问控制漏洞
CVE-2009-1081Sun Java System Identity Manager多个跨站脚本漏洞
CVE-2009-1075Sun Java System Identity Manager 忘记口令功能信息泄露漏洞
CVE-2009-1074Sun Java System Identity Manager 非加密传输信息泄露漏洞
CVE-2009-0215IBM Access Support ActiveX控件GetXMLValue()方式栈溢出漏洞
CVE-2009-1092GeoVision LiveAudio ActiveX控件GetAudioPlayingTime()方式代码执行漏洞
CVE-2009-1091Rapid Leech upload.php跨站脚本攻击漏洞
CVE-2009-1090Rapid Leech upload.php目录遍历和文件包含漏洞
CVE-2009-1089Rapid Leech upload.php绝对路径遍历漏洞
CVE-2009-1088Hannonhill Cascade Server XLST处理远程命令执行漏洞
CVE-2009-1087PPLive URI处理器LoadModule参数多个代码执行漏洞

Showing top 20 of 58 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-6523

No comments yet


Leave a comment