Vulnerabilities > CVE-2007-4047 - Security Bypass vulnerability in Geoblog 1

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
geoblog
exploit available

Summary

geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which allows remote attackers to delete arbitrary comments, delete arbitrary blogs, and have other unspecified impact via a request with a valid id parameter.

Vulnerable Configurations

Part Description Count
Application
Geoblog
1

Exploit-Db

  • descriptiongeoBlog MOD_1.0 deletecomment.php id Variable Remote Arbitrary Comment Deletion. CVE-2007-4047. Webapps exploit for php platform
    idEDB-ID:30320
    last seen2016-02-03
    modified2007-07-19
    published2007-07-19
    reporterjoseph.giron13
    sourcehttps://www.exploit-db.com/download/30320/
    titlegeoBlog MOD_1.0 deletecomment.php id Variable Remote Arbitrary Comment Deletion
  • descriptiongeoBlog MOD_1.0 deleteblog.php id Variable Remote Arbitrary Blog Deletion. CVE-2007-4047. Webapps exploit for php platform
    idEDB-ID:30321
    last seen2016-02-03
    modified2007-07-19
    published2007-07-19
    reporterjoseph.giron13
    sourcehttps://www.exploit-db.com/download/30321/
    titlegeoBlog MOD_1.0 deleteblog.php id Variable Remote Arbitrary Blog Deletion