vendor:
Forums
by:
Bl0od3r
7,5
CVSS
HIGH
ChangePass
264
CWE
Product Name: Forums
Affected Version From: 3x
Affected Version To: 3x
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
iPrimal Forums Users(ChangePass) 3xPl0!t
This exploit allows an attacker to create a new user account with administrative privileges on a vulnerable iPrimal Forums installation. The attacker can then use the newly created account to gain access to the administrative panel and perform malicious activities.
Mitigation:
Upgrade to the latest version of iPrimal Forums and ensure that all user accounts have strong passwords.