PT-2007-4885 · Avtutorial · Av Tutorial Script
Dj7Xpl
·
Published
2007-07-10
·
Updated
2017-09-29
·
CVE-2007-3630
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
AV Tutorial Script (avtutorial) version 1.0
Description
The issue allows remote attackers to change passwords for arbitrary users without requiring authentication or knowledge of the old password. This is achieved by modifying the
password parameter in the "changePW.php" file.Recommendations
For AV Tutorial Script (avtutorial) version 1.0, consider implementing authentication and old password verification requirements for the password change functionality in the "changePW.php" file to prevent unauthorized password changes. As a temporary workaround, restrict access to the "changePW.php" file until a proper fix is implemented.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Av Tutorial Script