2z project 0.9.6.1 allows attackers to change the password without supplying the old password.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/27057 | vdb entry exploit |
http://securityreason.com/securityalert/3514 | third party advisory |
http://www.securityfocus.com/archive/1/485590/100/0/threaded | mailing list |
http://2z-project.ru/forum/viewtopic.php?pid=8309 |