peter bassill · operator
$ cve CVE-2007-1364 JSON

CVE-2007-1364 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS2.25% — more likely to be exploited than 82% of all CVEs
On CISA KEVno
Public exploityes
Published2007-04-11
Last modified2026-06-16

Affected (1)

VendorProduct
dropafewdropafew

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD