6.4
CVSSv2

CVE-2007-4637

Published: 31/08/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote malicious users to make unspecified changes via an unknown series of steps.

Vulnerable Product Search on Vulmon Subscribe to Product

xgb xgb 2.0

Exploits

/* * * xGB 20 (xGBphp) Remote Permission Bypass Vulnerability * Bug discovered by DarkFuneral * wwwdarkfuneral89altervistaorg/ * * Affected Software: xGB * CMS Site: "i don't know! :P" * Severity: Critical * Description: An attacker can edit all message in xGB * Google Dork: allinurl:"xGbphp" * * E-Mail: darkfuneral89@gmailcom * * * ...