home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter.
Link | Tags |
---|---|
http://securityreason.com/securityalert/1005 | third party advisory |
http://www.securityfocus.com/archive/1/435284/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26833 | vdb entry |
http://www.nukedx.com/?viewdoc=36 | exploit vendor advisory |
http://www.securityfocus.com/archive/1/435300/100/0/threaded | mailing list |