6.4
CVSSv2

CVE-2007-1364

Published: 11/04/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

DropAFew prior to 0.2.1 does not require authorization for certain privileged actions, which allows remote malicious users to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.

Vulnerable Product Search on Vulmon Subscribe to Product

dropafew dropafew

Exploits

source: wwwsecurityfocuscom/bid/23400/info DropAFew is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the ...
DropAFew versions 02 and below suffer from SQL injection vulnerabilities ...