vendor:
Simple Forum
by:
cOndemned
7.5
CVSS
HIGH
Change Admin Password Exploit
N/A
CWE
Product Name: Simple Forum
Affected Version From: 1.6.2 Final
Affected Version To: 1.6.2 Final
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
LoveCMS 1.6.2 Final (Simple Forum 3.1d) Change Admin Password Exploit
This exploit changes forum admin password (ex. attacker will be able to delete threads/topics) and sets allowHTML to true (attacks such as XSS/HTML Injection will be possible).
Mitigation:
Upgrade to the latest version of LoveCMS and Simple Forum.