CVE-2008-3033

Rss Aggregator - Authentication Bypass

Title source: rule

Description

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/32003

Scores

EPSS 0.0186
EPSS Percentile 82.9%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

rss_aggregator/rss_aggregator

Timeline

Published Jul 07, 2008
Tracked Since Feb 18, 2026