« Volver al listado

CVE-2008-3451

Estado: ModificadaMedia (4)—

PhpWebGallery 1.7.0 y 1.7.1, permite a usuarios utenticados remotamente con privilegios de notificador/consejero, obtener direcciones reales de e-mail de otros usuarios editando los perfiles de usuario.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3451",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-08-04T19:41:00.000",
  "references": [
    {
      "url": "http://bugs.phpwebgallery.net/view.php?id=769",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://forum.phpwebgallery.net/viewtopic.php?id=13545",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31232",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2008/08/01/3",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30431",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44101",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.phpwebgallery.net/view.php?id=769",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://forum.phpwebgallery.net/viewtopic.php?id=13545",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31232",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2008/08/01/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30431",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44101",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile."
    },
    {
      "lang": "es",
      "value": "PhpWebGallery 1.7.0 y 1.7.1, permite a usuarios utenticados remotamente con privilegios de notificador/consejero, obtener direcciones reales de e-mail de otros usuarios editando los perfiles de usuario."
    }
  ],
  "lastModified": "2026-06-16T22:55:51.343",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phpwebgallery:phpwebgallery:1.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC5256C5-8612-4961-B813-D560D59E59EC"
            },
            {
              "criteria": "cpe:2.3:a:phpwebgallery:phpwebgallery:1.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "874E8A29-1530-4744-A466-05AC7E543EC5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}