{ "id": "CVE-2007-3630", "sourceIdentifier": "cve@mitre.org", "published": "2007-07-10T00:30:00.000", "lastModified": "2017-09-29T01:29:04.797", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter." }, { "lang": "es", "value": "changePW.php en AV Tutorial Script (avtutorial) 1.0 no requiere validaci\u00f3n o conocimiento de un contrase\u00f1a antig\u00fca para un cambio de contrase\u00f1a, lo cual permite a atacantes remotos cambiar las contrase\u00f1as para usuarios de su elecci\u00f3n a trav\u00e9s del par\u00e1metro password modificado." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 6.4 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:av_scripts:av_tutorial_script:1.0:*:*:*:*:*:*:*", "matchCriteriaId": "559571A2-F2B4-413B-8179-DF59D81A9AE4" } ] } ] } ], "references": [ { "url": "http://attrition.org/pipermail/vim/2007-July/001705.html", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/42461", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/24808", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35295", "source": "cve@mitre.org" }, { "url": "https://www.exploit-db.com/exploits/4163", "source": "cve@mitre.org" } ] }