CVE-2007-5913
JBC Explorer <7.20 RC1 - RCE
Title source: llmDescription
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.
Exploits (1)
References (8)
Scores
EPSS
0.1651
EPSS Percentile
94.8%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
jean_charles/jbc_explorer
< 7.20_rc1
Timeline
Published
Nov 10, 2007
Tracked Since
Feb 18, 2026