CVE-2007-2715
high · 10Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.
10
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2007-05-16
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| snaps_gallery | snaps_gallery | 1.4.4 |
Check a specific version with /api/v1/cve/match.
References
- http://0day.2600.ir/exploits/3900
- http://www.securityfocus.com/bid/23940
- http://www.vupen.com/english/advisories/2007/1781
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34300
- https://www.exploit-db.com/exploits/3900
- http://0day.2600.ir/exploits/3900
- http://www.securityfocus.com/bid/23940
- http://www.vupen.com/english/advisories/2007/1781
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34300
- https://www.exploit-db.com/exploits/3900
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-2715