CVE-2007-4637 EXPLOIT
6.4
MEDIUM · CVSS 2.0 · EPSS 2.2% (pctl 82)
Patch early
A public exploit exists.
Description
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.
Scoring
| CVSS | 6.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
| EPSS | 2.17% — more likely to be exploited than 82% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xgb | xgb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | xGB 2.0 - 'xGB.php' Remote Security Bypass | 2007-08-29 |
→ the Explorer · watch your stack · NVD