CVE-2000-1228
טרם דורגה
תיאור (מקור, אנגלית)
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
מדדים
- EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-23/9/2026
מוצרים מושפעים
phorum: phorum
קישורים
- http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html ExploitPatchVendor Advisory
- http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html ExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/2271 ExploitPatch
- http://www.securityfocus.com/bid/2271 ExploitPatch
- http://hispahack.ccc.de/mi020.html
- http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm
- http://hispahack.ccc.de/mi020.html
- http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm