vendor:
MetaBBS
by:
SecurityFocus
7.5
CVSS
HIGH
Password Modification Vulnerability
259
CWE
Product Name: MetaBBS
Affected Version From: MetaBBS 0.11
Affected Version To: Other versions may also be affected.
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
MetaBBS Password Modification Vulnerability
MetaBBS is prone to a vulnerability that lets attackers modify arbitrary user passwords because it fails to adequately secure access to administrative functionality. Exploiting this issue may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Mitigation:
Ensure that access to administrative functionality is adequately secured.