CVE-2008-6673

Quickersite - Access Control

Title source: rule

Description

asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact address, via the saveAdmin; and (3) modify the site design via the saveDesign action.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/5733

Scores

EPSS 0.0180
EPSS Percentile 82.8%

Details

CWE
CWE-264
Status published
Products (1)
quickersite/quickersite 1.8.5
Published Apr 08, 2009
Tracked Since Feb 18, 2026