UserProfile.cs in Ultraapps Issue Manager before 2.1 allows remote authenticated users to gain administrator privileges by modifying the original (1) p_User_user_id and (2) User_user_id parameters to UserProfile.aspx, then modifying the password field.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/419910/100/0/threaded | mailing list |
http://www.vupen.com/english/advisories/2005/3031 | vdb entry |
http://www.securityfocus.com/bid/15976 | vdb entry patch |
http://www.irmplc.com/advisory013.htm | |
http://secunia.com/advisories/18174 | third party advisory |