Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.exploit-db.com/exploits/9425 | exploit |
http://secunia.com/advisories/33686 | third party advisory vendor advisory |