CVE-2008-0266
Eticket - CSRF
Title source: ruleDescription
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by L4teral · htmlwebappsphp
https://www.exploit-db.com/exploits/30994
References (5)
Scores
EPSS
0.0040
EPSS Percentile
60.3%
Classification
CWE
CWE-352
Status
draft
Affected Products (1)
eticket/eticket
Timeline
Published
Jan 15, 2008
Tracked Since
Feb 18, 2026