vendor:
NetRisk
by:
Cod3rZ
9.3
CVSS
HIGH
Remote Password Change
287
CWE
Product Name: NetRisk
Affected Version From: 1.9.2007
Affected Version To: 1.9.2007
Patch Exists: YES
Related CWE: N/A
CPE: a:netrisk:netrisk:1.9.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
NetRisk 1.9.7 Remote Password Change Exploit
This exploit allows an attacker to change the password of any user on the NetRisk 1.9.7 board. The vulnerability is due to a lack of authentication when changing the password. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the board. This will allow the attacker to change the password of any user on the board.
Mitigation:
Upgrade to the latest version of NetRisk.