5
CVSSv2

CVE-2007-5816

Published: 05/11/2007 Updated: 15/11/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

dialog.php in CONTENTCustomizer 3.1mp and previous versions allows remote malicious users to obtain sensitive author credentials by making a request with an editauthor action, then reading the value of the newlocalpassword password input field in the HTML source of the resulting page.

Vulnerable Product Search on Vulmon Subscribe to Product

contentcustomizer contentcustomizer 3.1mp

Exploits

source: wwwsecurityfocuscom/bid/26291/info CONTENTCustomizer is prone to an information-disclosure vulnerability An attacker can exploit this issue to access sensitive information that may lead to further attacks CONTENTCustomizer 31mp is vulnerable; other versions may also be affected wwwexamplecom/dialogphp?action=edit ...