The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.
References
Configurations
Information
Published : 2012-08-11 17:55
Updated : 2017-08-28 18:32
NVD link : CVE-2012-4035
Mitre link : CVE-2012-4035
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
pbboard
- pbboard