Back to search
CVE-2012-4035
Published: Aug 12, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.htbridge.com/advisory/HTB23101
x_refsource_MISC
http://www.pbboard.com/forums/t10353.html
x_refsource_MISC
84481
vdb-entry
x_refsource_OSVDB
54916
vdb-entry
x_refsource_BID
http://www.pbboard.com/forums/t10352.html
x_refsource_MISC
pbboard-index-security-bypass(77506)
vdb-entry
x_refsource_XF
50153
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now