account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11363 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17682 | vdb entry |
http://www.securitytracker.com/alerts/2004/Oct/1011597.html | exploit vdb entry vendor advisory |
http://www.osvdb.org/10663 | vdb entry |