Логотип exploitDog
bind:CVE-2007-3630
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2007-3630

Количество 2

Количество 2

nvd логотип

CVE-2007-3630

больше 18 лет назад

changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.

CVSS2: 6.4
EPSS: Низкий
github логотип

GHSA-86w8-6xgq-q96x

почти 4 года назад

changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-3630

changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.

CVSS2: 6.4
7%
Низкий
больше 18 лет назад
github логотип
GHSA-86w8-6xgq-q96x

changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.

7%
Низкий
почти 4 года назад

Уязвимостей на страницу