CVE-2007-5913

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
10/11/2007
Last modified:
09/04/2025

Description

dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jean_charles:jbc_explorer:*:*:*:*:*:*:*:* 7.20_rc1 (including)