Vulnerability Description
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snaps Gallery | Snaps Gallery | 1.4.4 |
References
- http://0day.2600.ir/exploits/3900
- http://www.securityfocus.com/bid/23940
- http://www.vupen.com/english/advisories/2007/1781
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34300
- https://www.exploit-db.com/exploits/3900
- http://0day.2600.ir/exploits/3900
- http://www.securityfocus.com/bid/23940
- http://www.vupen.com/english/advisories/2007/1781
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34300
- https://www.exploit-db.com/exploits/3900
FAQ
What is CVE-2007-2715?
CVE-2007-2715 is a vulnerability with a CVSS score of 10.0 (HIGH). Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.
How severe is CVE-2007-2715?
CVE-2007-2715 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2715?
Check the references section above for vendor advisories and patch information. Affected products include: Snaps Gallery Snaps Gallery.