CVE-2008-3033
Rss Aggregator - Authentication Bypass
Title source: ruleDescription
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/32003
References (4)
Scores
EPSS
0.0186
EPSS Percentile
82.9%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
rss_aggregator/rss_aggregator
Timeline
Published
Jul 07, 2008
Tracked Since
Feb 18, 2026