admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via a modified user_id field.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.exploit-db.com/exploits/8774 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50722 | vdb entry |
http://www.securityfocus.com/bid/35079 | vdb entry |