« Volver al listado

CVE-2007-4260

Estado: ModificadaMedia (5)—

EZPhotoSales 1.9.3 y anteriores tiene una cuenta "admin" por defecto para las galerías, lo cual permite a atacantes remotos acceder a galerías de su elección especificando este nombre de usuario.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4260",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-08T23:17:00.000",
  "references": [
    {
      "url": "http://securityreason.com/securityalert/2985",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.airscanner.com/security/07080601_ezphotosales.htm",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.informit.com/guides/content.asp?g=security&seqNum=267",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.informit.com/guides/content.asp?g=security&seqNum=268",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/475678/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35837",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/2985",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.airscanner.com/security/07080601_ezphotosales.htm",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.informit.com/guides/content.asp?g=security&seqNum=267",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.informit.com/guides/content.asp?g=security&seqNum=268",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/475678/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35837",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EZPhotoSales 1.9.3 and earlier has a default \"admin\" account for galleries, which allows remote attackers to access arbitrary galleries by specifying this username."
    },
    {
      "lang": "es",
      "value": "EZPhotoSales 1.9.3 y anteriores tiene una cuenta \"admin\" por defecto para las galerías, lo cual permite a atacantes remotos acceder a galerías de su elección especificando este nombre de usuario."
    }
  ],
  "lastModified": "2026-06-16T22:43:41.800",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ez_photo_sales:ez_photo_sales:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F5E844-573E-44B7-9A58-83B4D44CCCDC",
              "versionEndIncluding": "1.9.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}