CVE-2007-0681
Last modified
CVE-2007-0681 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.. EPSS estimates a 5.04% chance of exploitation in the next 30 days.
Description
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Extcalendar Project | Extcalendar | <= 2 |
References
- https://osvdb.org/38130Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32035Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/3239Exploit, Third Party Advisory, VDB Entry
- https://osvdb.org/38130Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32035Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/3239Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0681?
How severe is CVE-2007-0681?
How do I fix CVE-2007-0681?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0675A certain ActiveX control in sapi.dll (aka the Speech API) i…
- CVE-2007-0676SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 a…
- CVE-2007-0677PHP remote file inclusion vulnerability in fw/class.Quick_Co…
- CVE-2007-0678SQL injection vulnerability in windows.asp in Fullaspsite As…
- CVE-2007-0679PHP remote file inclusion vulnerability in lang/leslangues.p…
- CVE-2007-0680PHP remote file inclusion vulnerability in includes/function…
- CVE-2007-0682PHP remote file inclusion vulnerability in theme/include_mod…
- CVE-2007-0683PHP remote file inclusion vulnerability in includes/function…
- CVE-2007-0684PHP remote file inclusion vulnerability in portal.php in Cer…
- CVE-2007-0685Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2…
- CVE-2007-0686The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w2…
- CVE-2007-0687SQL injection vulnerability in i-search.php in Michelle's L2…
Are you affected by CVE-2007-0681?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
