CVE-2005-4688

PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an address change via a hijacked login session.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:punbb:punbb:1.2.9:*:*:*:*:*:*:*

Information

Published : 2005-12-30 21:00

Updated : 2008-09-05 13:57


NVD link : CVE-2005-4688

Mitre link : CVE-2005-4688


JSON object : View

Advertisement

dedicated server usa

Products Affected

punbb

  • punbb