Back to search
CVE-2007-1364
Published: Apr 11, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
24861
third-party-advisory
x_refsource_SECUNIA
dropafew-editlogcal-information-disclosure(33561)
vdb-entry
x_refsource_XF
23400
vdb-entry
x_refsource_BID
https://www.cynops.de/advisories/CVE-2007-1363.txt
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now