PT-2007-4885 · Avtutorial · Av Tutorial Script

Dj7Xpl

·

Publicado

2007-07-10

·

Atualizado

2017-09-29

·

CVE-2007-3630

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions AV Tutorial Script (avtutorial) version 1.0
Description The issue allows remote attackers to change passwords for arbitrary users without requiring authentication or knowledge of the old password. This is achieved by modifying the password parameter in the "changePW.php" file.
Recommendations For AV Tutorial Script (avtutorial) version 1.0, consider implementing authentication and old password verification requirements for the password change functionality in the "changePW.php" file to prevent unauthorized password changes. As a temporary workaround, restrict access to the "changePW.php" file until a proper fix is implemented.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3630

Produtos afetados

Av Tutorial Script