Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-6237

EPSS 2.02% · P84
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-6237

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
DeluxeBB CP.PHP 安全绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DeluxeBB中的cp.php不能确定在一个文件更新中membercookie参数相当于验证会员,远程验证用户可以借助一个修改的membercookie参数改变任意账户的email地址,该漏洞不同于CVE-2006-4078。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-6237

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-6237

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-12-04 · 34 CVEs total

CVE-2007-6216Sun Solaris 10 FCP(7D) and DEVFS(7FS) 本地拒绝服务漏洞
CVE-2007-6220Typespeed Malformed Packet Divide By Zero拒绝服务漏洞
CVE-2007-6221TuMusika TuMusika Evolution TuMusika Evolution 信息泄露漏洞
CVE-2007-6222CRM-CTT CheckCustomerAccess 安全绕过漏洞
CVE-2007-6223PhpBBGarage Garage.PHP SQL注入漏洞
CVE-2007-6212KML share Region.PHP 远程文件包含漏洞
CVE-2007-6213WebED Multiple Index.PHP 多个远程目录遍历漏洞
CVE-2007-6214LearnLoop File_download.PHP 远程文件包含漏洞
CVE-2007-6215Web-MeetMe Play.PHP 多个本地文件包含漏洞
CVE-2007-6219IBM Tivoli Netcool Security Manager 跨站脚本漏洞
CVE-2007-6217Irola My-Time UserID and Password 多个SQL注入漏洞
CVE-2007-6210ZABBIX daemon_start 本地特权提升漏洞
CVE-2007-6211Debian GNU/Linux SING Log Option 本地特权提升漏洞
CVE-2007-6206Linux Kernel 信息泄露漏洞
CVE-2007-6207Xen mov_to_rr调用RID本地绕过安全限制漏洞
CVE-2007-6208Claws Mail 非安全临时文件创建漏洞
CVE-2007-6209Zsh 非安全临时文件创建漏洞
CVE-2007-6224Realplayer RealAudioObjects.RealAudio ActiveX控件拒绝服务漏洞
CVE-2007-6218Ossigeno CMS 输入验证错误漏洞
CVE-2007-6239Squid代理缓存更新回复处理远程拒绝服务漏洞

Showing top 20 of 34 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-6237

No comments yet


Leave a comment