CVE-2008-5708
SlimCMS 1.0.0 - Open Redirect
Title source: llmDescription
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
Exploits (1)
References (4)
Scores
EPSS
0.0466
EPSS Percentile
89.3%
Details
CWE
CWE-287
Status
published
Products (1)
slimcms/slimcms
1.0.0
Published
Dec 24, 2008
Tracked Since
Feb 18, 2026