CVE-2011-2674

BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.10:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.3:*:*:*:*:*:*:*

History

15 Jul 2021, 14:23

Type Values Removed Values Added
CPE cpe:2.3:a:e-catchup:basercms:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.11.2:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.11:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.9.1:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:*:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.9:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.11.1:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.11.3:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.10:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.7.1:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:e-catchup:basercms:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.3:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.10:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.6:*:*:*:*:*:*:*

Information

Published : 2011-10-02 02:53

Updated : 2024-02-04 17:54


NVD link : CVE-2011-2674

Mitre link : CVE-2011-2674

CVE.ORG link : CVE-2011-2674


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-264

Permissions, Privileges, and Access Controls