vendor:
Free Monthly Websites 2.0
by:
Yassin Aboukir
7,5
CVSS
HIGH
Remote Password Change
20
CWE
Product Name: Free Monthly Websites 2.0
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:freemonthlywebsites2.com:free_monthly_websites_2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Firefox, Google Chrome, Internet Explorer
2013
Free Monthly Websites 2.0 Administrator Remote Password Change
A vulnerability in Free Monthly Websites 2.0 allows an attacker to remotely change the administrator password. The vulnerability exists due to insufficient validation of user-supplied input in the 'admin/file_io.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious values for the 'admin_password' and 'admin_password_confirm' parameters. This will allow the attacker to change the administrator password.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of Free Monthly Websites 2.0.