CVE-2011-0503
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.1%
from disclosure to weapon0 days
Published on NVDJan 20
1st PoCJan 11
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php or (2) change user permissions via admin/accounting.php. NOTE: some of these details are obtained from third party information.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/15968unverifiedcve_referencewww.exploit-db.com/exploits/15968unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.