{ "id": "CVE-2008-2297", "sourceIdentifier": "cve@mitre.org", "published": "2008-05-18T14:20:00.000", "lastModified": "2025-04-09T00:30:58.490", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to \"\", which is present in the password file and probably passes an insufficient comparison." }, { "lang": "es", "value": "El archivo admin.php en Rantx permite a atacantes remotos evitar la autentificaci\u00f3n y obtener privilegios estableciendo la cookie logininfo a \"\", lo que est\u00e1 en el archivo password y probablemente pase una comparaci\u00f3n insuficiente." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "baseScore": 7.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-264" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:roticv:rantx:1.0:*:*:*:*:*:*:*", "matchCriteriaId": "1999CDAB-AECC-4706-B2C0-BD27CE46CD31" } ] } ] } ], "references": [ { "url": "http://secunia.com/advisories/30279", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/29243", "source": "cve@mitre.org", "tags": [ "Exploit" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42464", "source": "cve@mitre.org" }, { "url": "https://www.exploit-db.com/exploits/5628", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/30279", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/29243", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42464", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://www.exploit-db.com/exploits/5628", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }