peter bassill · operator
$ cve CVE-2007-2715 JSON

CVE-2007-2715 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 10.4% (pctl 96)

Patch early

A public exploit exists.

Description

Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS10.39% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2007-05-16
Last modified2026-06-16

Affected (1)

VendorProduct
snaps gallerysnaps gallery

Public exploits

SourceTitleDate
exploit-dbSnaps! Gallery 1.4.4 - Remote User Pass Change2007-05-11

References

→ the Explorer  ·  watch your stack  ·  NVD