The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.
References
Configurations
Information
Published : 2012-08-12 00:55
Updated : 2017-08-29 01:32
NVD link : CVE-2012-4035
Mitre link : CVE-2012-4035
JSON object : View
Products Affected
pbboard
- pbboard
CWE
CWE-264
Permissions, Privileges, and Access Controls
