9
CVE-2007-6237
- EPSS 2.74%
- Veröffentlicht 04.12.2007 18:46:00
- Zuletzt bearbeitet 16.06.2026 22:47:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.74% | 0.842 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://secunia.com/advisories/27794
http://securityreason.com/securityalert/3416
http://www.securityfocus.com/archive/1/484205/100/0/threaded
http://www.securityfocus.com/bid/26572