Vulnerabilities > CVE-2007-1364 - SQL Injection vulnerability in DropAFew

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
dropafew
exploit available

Summary

DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.

Vulnerable Configurations

Part Description Count
Application
Dropafew
1

Exploit-Db

descriptionDropAFew 0.2 newaccount2.php Arbitrary Account Creation. CVE-2007-1364. Webapps exploit for php platform
idEDB-ID:29831
last seen2016-02-03
modified2007-04-10
published2007-04-10
reporterAlexander Klink
sourcehttps://www.exploit-db.com/download/29831/
titleDropAFew 0.2 newaccount2.php Arbitrary Account Creation

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/55830/AKLINK-SA-2007-002.txt
idPACKETSTORM:55830
last seen2016-12-05
published2007-04-11
reporterAlexander Klink
sourcehttps://packetstormsecurity.com/files/55830/AKLINK-SA-2007-002.txt.html
titleAKLINK-SA-2007-002.txt