vendor:
wPortfolio
by:
G4N0K
7.5
CVSS
HIGH
OS
N/A
CWE
Product Name: wPortfolio
Affected Version From: 0.3
Affected Version To: 0.3
Patch Exists: YES
Related CWE: N/A
CPE: a:wportfolio:wportfolio
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2008
wPortfolio <= 0.3 Admin Password Changing Exploit
wPortfolio is a free and open source web-based application written in PHP, designed to help you easily create and maintain your own portfolio website. A vulnerability exists in wPortfolio version 0.3 which allows an attacker to change the admin password. This can be exploited by sending a specially crafted HTTP POST request to the 'admin.php' script with the 'action' parameter set to 'change_password' and the 'password' parameter set to the new password.
Mitigation:
Upgrade to the latest version of wPortfolio