CVE-2008-4427

Phlatline Personal Information Manager < 1.0 - Authentication Bypass

Title source: rule

Description

changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Stack · textwebappsphp
https://www.exploit-db.com/exploits/6231
exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/8105
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/6215

Scores

EPSS 0.0607
EPSS Percentile 90.6%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

phlatline/personal_information_manager < 1.0

Timeline

Published Oct 03, 2008
Tracked Since Feb 18, 2026