Vulnerability Description
Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elite Bulletin Board | Elite Bulletin Board | 1.0.8 |
References
- http://osvdb.org/37819
- http://secunia.com/advisories/25926Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=520558&group_id=175118Patch
- http://www.securityfocus.com/bid/24763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35261
- http://osvdb.org/37819
- http://secunia.com/advisories/25926Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=520558&group_id=175118Patch
- http://www.securityfocus.com/bid/24763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35261
FAQ
What is CVE-2007-3591?
CVE-2007-3591 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably relate...
How severe is CVE-2007-3591?
CVE-2007-3591 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3591?
Check the references section above for vendor advisories and patch information. Affected products include: Elite Bulletin Board Elite Bulletin Board.