Back to search
CVE-2009-1767
Published: May 22, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
34977
vdb-entry
x_refsource_BID
35090
third-party-advisory
x_refsource_SECUNIA
8691
exploit
x_refsource_EXPLOIT-DB
tmc-edituser-security-bypass(50561)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now