CVE-2008-5708

Publication date

2008-12-24 17:00:00

Family

mitre

State

PUBLISHED

Description

redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.