Lucene search

K
cve[email protected]CVE-2007-4416
HistoryAug 18, 2007 - 9:17 p.m.

CVE-2007-4416

2007-08-1821:17:00
web.nvd.nist.gov
36
bellabook
bellabuffs
remote attackers
administrative privileges
cve-2007-4416
vulnerability
authentication
exploit code
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.5%

captcha.php in BellaBook (aka BellaBuffs) allows remote attackers to obtain administrative privileges by sending the admin’s username (admin_name) in a pheap_login cookie. NOTE: the vendor disputes this vulnerability because authentication data is derived from the admin_pass and secret variables, in addition to the admin_name; and because the exploit code is designed for an unrelated application

Affected configurations

NVD
Node
jemjabellabellabook

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.5%

Related for CVE-2007-4416