CVE-2008-2920

Eztechhelp Ezcms < 1.2 - Authentication Bypass

Title source: rule
STIX 2.1

Description

admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.

Exploits (1)

exploitdb WRITEUP VERIFIED
by t0pP8uZz · textwebappsphp
https://www.exploit-db.com/exploits/5819

References (4)

Core 4
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29738
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43091
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5819

Scores

EPSS 0.0608
EPSS Percentile 90.8%

Details

CWE
CWE-287
Status published
Products (1)
ezcms/eztechhelp_ezcms < 1.2
Published Jun 30, 2008
Tracked Since Feb 18, 2026