CVE-2008-7156

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/09/2009
Last modified:
09/04/2025

Description

EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ekinboard:ekinboard:*:*:*:*:*:*:*:* 1.1.0 (including)