CVE-2008-0266 describes a Cross-Site Request Forgery (CSRF) vulnerability in admin.php within eTicket version 1.5.5.2. This flaw could allow a remote attacker to change the administrative password and potentially execute other administrative functions. The vulnerability has a CVSS score of 2.6, indicating low severity, primarily due to the high attack complexity requiring either knowledge of the old password or a separate SQL injection. While exploit code exists on ExploitDB, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.5.2CPE matchmatch criteria | cpe:2.3:a:eticket:eticket:1.5.5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.