CVE-2007-2715

Snaps! Gallery 1.4.4 - Unauthenticated Arbitrary Username and Password Change via Admin/users.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2715. PoCs published by Dj7xpl.

AI-analyzed exploit summary This exploit targets a vulnerability in Snaps! Gallery 1.4.4, allowing remote attackers to change user passwords without authentication by sending a crafted HTTP POST request. The exploit constructs a multipart/form-data request to modify user credentials via the Admin/users.php endpoint.

Description

Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dj7xpl · phpwebappsphp
https://www.exploit-db.com/exploits/3900

This exploit targets a vulnerability in Snaps! Gallery 1.4.4, allowing remote attackers to change user passwords without authentication by sending a crafted HTTP POST request. The exploit constructs a multipart/form-data request to modify user credentials via the Admin/users.php endpoint.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Snaps! Gallery 1.4.4
No auth needed
Prerequisites: Network access to the target server · Knowledge of the target path and user ID
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34300
Various Sources x_refsource_misc
http://0day.2600.ir/exploits/3900
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1781
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23940
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3900

Scores

EPSS 0.1019
EPSS Percentile 95.1%

Details

Status published
Products (1)
snaps_gallery/snaps_gallery 1.4.4
Published May 16, 2007
Tracked Since Feb 18, 2026