peter bassill · operator
$ cve CVE-2007-3630 JSON

CVE-2007-3630 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS2.33% — more likely to be exploited than 83% of all CVEs
On CISA KEVno
Public exploityes
Published2007-07-10
Last modified2026-06-16

Affected (1)

VendorProduct
av scriptsav tutorial script

Public exploits

SourceTitleDate
exploit-dbAV Tutorial Script 1.0 - Remote User Pass Change2007-07-08

References

→ the Explorer  ·  watch your stack  ·  NVD