The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.htbridge.com/advisory/HTB23101 | exploit |
http://www.pbboard.com/forums/t10353.html | url repurposed vendor advisory |
http://osvdb.org/84481 | vdb entry |
http://www.securityfocus.com/bid/54916 | vdb entry exploit |
http://www.pbboard.com/forums/t10352.html | url repurposed |
https://exchange.xforce.ibmcloud.com/vulnerabilities/77506 | vdb entry |
http://secunia.com/advisories/50153 | third party advisory vendor advisory |