« Back to list

CVE-2007-0192

Status: ModifiedHigh (7.5)—

Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2007-0192",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-01-12T05:04:00.000",
  "references": [
    {
      "url": "http://osvdb.org/33400",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/2137",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/455894/100/100/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/33400",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/2137",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/455894/100/100/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the \"All Guests are Admin\" attack."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en la operación save_main en la sección ad_perms en admin.php en MKPortal permite a atacantes remotos modificar configuraciones de prvilegio, como se demuestra usando un getURL de admin.php con un fichero .swf contenido en un elemento IFRAME, también conocido como el ataque \"Todos los invitados son administradores\"."
    }
  ],
  "lastModified": "2026-06-16T22:35:05.700",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mkportal:mkportal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FE41A57-FD91-4DC1-9C90-ADB513F95A39"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}