VulnerabilityModified
CVE-2007-3592
PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.
MEDIUM 6.5EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- elite bulletin board/elite bulletin board
- Source
- cve@mitre.org
References
- http://osvdb.org/37820
- http://secunia.com/advisories/25926Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=520558&group_id=175118Patch
- http://www.securityfocus.com/bid/24763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35262
- http://osvdb.org/37820
- http://secunia.com/advisories/25926Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=520558&group_id=175118Patch
- http://www.securityfocus.com/bid/24763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35262
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.