VulnerabilityModified
CVE-2007-3591
Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks.
MEDIUM 5.0EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- elite bulletin board/elite bulletin board
- Source
- cve@mitre.org
References
- http://osvdb.org/37819
- http://secunia.com/advisories/25926Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=520558&group_id=175118Patch
- http://www.securityfocus.com/bid/24763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35261
- http://osvdb.org/37819
- http://secunia.com/advisories/25926Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=520558&group_id=175118Patch
- http://www.securityfocus.com/bid/24763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35261
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.