Vulnerabilities > CVE-2007-3643 - Unspecified vulnerability in AV Scripts AV Arcade 2.1B

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
av-scripts
critical

Summary

admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions.

Vulnerable Configurations

Part Description Count
Application
Av_Scripts
1