CVE-2007-0697
ACGVannu < 1.3 - Unauthenticated Password and Profile Modification via ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0697. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a remote password change vulnerability in ACGVannu <= 1.3 by manipulating the 'index2.php' script with crafted parameters. The attacker can change the password of any user by providing the user ID and new credentials in the URL.
Description
index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a remote password change vulnerability in ACGVannu <= 1.3 by manipulating the 'index2.php' script with crafted parameters. The attacker can change the password of any user by providing the user ID and new credentials in the URL.