CVE-2007-4240
Last modified
CVE-2007-4240 is a vulnerability of currently unknown severity. The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to delete administrative users and have other unspecified impact via certain requests to (1) admin/departments.php, (2) admin/operators.php, and other unspecified scripts. NOTE: some of these details are obtained from third party information.. EPSS estimates a 1.36% chance of exploitation in the next 30 days.
Description
The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to delete administrative users and have other unspecified impact via certain requests to (1) admin/departments.php, (2) admin/operators.php, and other unspecified scripts. NOTE: some of these details are obtained from third party information.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Help Center Live | Help Center Live | 2.1.3a |
References
- http://secunia.com/advisories/26352Vendor Advisory
- http://secunia.com/advisories/26352Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4240?
How severe is CVE-2007-4240?
How do I fix CVE-2007-4240?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4234Unspecified vulnerability in Camera Life before 2.6 allows r…
- CVE-2007-4235Multiple PHP remote file inclusion vulnerabilities in VietPH…
- CVE-2007-4236Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.…
- CVE-2007-4237Buffer overflow in the atm subset in arp in devices.common.I…
- CVE-2007-4238AIX 5.2 and 5.3 install pioinit with user and group ownershi…
- CVE-2007-4239Cross-site scripting (XSS) vulnerability in user/forgotPassS…
- CVE-2007-4241Buffer overflow in ldcconn in Hewlett-Packard (HP) Controlle…
- CVE-2007-4242The pop3 Proxy in Astaro Security Gateway (ASG) 7 does not p…
- CVE-2007-4243Unspecified vulnerability in pfilter-reporter.pl in Astaro S…
- CVE-2007-4244PHP remote file inclusion vulnerability in langset.php in J!…
- CVE-2007-4245Cross-site scripting (XSS) vulnerability in Search.php in Di…
- CVE-2007-4246Unspecified vulnerability, possibly a buffer overflow, in Ju…
Are you affected by CVE-2007-4240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
