vendor:
Active Bulletin Board
by:
ajann
7,5
CVSS
HIGH
Remote User Pass Change Exploit
N/A
CWE
Product Name: Active Bulletin Board
Affected Version From: v1.1 beta2
Affected Version To: v1.1 beta2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Active Bulletin Board v1.1 beta2 (doprofiledit.asp) Remote User Pass Change Exploit
This exploit allows a remote attacker to change the password of a user on a vulnerable Active Bulletin Board v1.1 beta2 system. The attacker can send a specially crafted POST request to the doprofiledit.asp script, which contains the new password for the user. The exploit requires the ID and UsrName of the user to be known, which can be obtained from the admin.asp page.
Mitigation:
Upgrade to the latest version of Active Bulletin Board v1.1 beta2