HIGH · 10.0

CVE-2007-2715

Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.

Vulnerability Description

Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Snaps GallerySnaps Gallery1.4.4

References

FAQ

What is CVE-2007-2715?

CVE-2007-2715 is a vulnerability with a CVSS score of 10.0 (HIGH). Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.

How severe is CVE-2007-2715?

CVE-2007-2715 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2715?

Check the references section above for vendor advisories and patch information. Affected products include: Snaps Gallery Snaps Gallery.