peter bassill · operator
$ cve CVE-2007-0681 JSON

CVE-2007-0681 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.2% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-522
On CISA KEVno
Public exploityes
Published2007-02-03
Last modified2026-06-16

Affected (1)

VendorProduct
extcalendar projectextcalendar

Public exploits

SourceTitleDate
exploit-dbExtcalendar 2 - 'profile.php' Remote User Pass Change2007-01-31

References

→ the Explorer  ·  watch your stack  ·  NVD