{"api_version":"1","generated_at":"2026-07-23T09:36:33+00:00","cve":"CVE-2008-5219","urls":{"html":"https://cve.report/CVE-2008-5219","api":"https://cve.report/api/cve/CVE-2008-5219.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5219","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5219"},"summary":{"title":"CVE-2008-5219","description":"The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-11-25 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/49885","name":"http://osvdb.org/49885","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/4634","name":"http://securityreason.com/securityalert/4634","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VideoScript <= 4.0.1.50 Admin Change Password Exploit - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32718","name":"http://secunia.com/advisories/32718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"VideoScript Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/7149","name":"https://www.exploit-db.com/exploits/7149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VideoScript <= 4.0.1.50 Admin Change Password Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5219","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5219","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5219","vulnerable":"1","versionEndIncluding":"4.0.1.50","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"videoscript","cpe5":"videoscript","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:49:11.880Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"49885","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/49885"},{"name":"32718","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32718"},{"name":"7149","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/7149"},{"name":"4634","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4634"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-11-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"49885","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/49885"},{"name":"32718","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32718"},{"name":"7149","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/7149"},{"name":"4634","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4634"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5219","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"49885","refsource":"OSVDB","url":"http://osvdb.org/49885"},{"name":"32718","refsource":"SECUNIA","url":"http://secunia.com/advisories/32718"},{"name":"7149","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/7149"},{"name":"4634","refsource":"SREASON","url":"http://securityreason.com/securityalert/4634"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5219","datePublished":"2008-11-25T18:09:00.000Z","dateReserved":"2008-11-25T00:00:00.000Z","dateUpdated":"2024-08-07T10:49:11.880Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-11-25 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:videoscript:videoscript:*:*:*:*:*:*:*:*","versionEndIncluding":"4.0.1.50","matchCriteriaId":"827F1C70-A82B-4E14-9973-29668E22EEF4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5219","Ordinal":"1","Title":"CVE-2008-5219","CVE":"CVE-2008-5219","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5219","Ordinal":"1","NoteData":"The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.","Type":"Description","Title":"CVE-2008-5219"},{"CveYear":"2008","CveId":"5219","Ordinal":"2","NoteData":"2008-11-25","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5219","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}