Active Bulletin Board Arbitrary User Password Change Vulnerability
BID:20611
Info
Active Bulletin Board Arbitrary User Password Change Vulnerability
| Bugtraq ID: | 20611 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2006 12:00AM |
| Updated: | Oct 19 2006 07:03PM |
| Credit: | ajann is credited with the discovery of this vulnerability. |
| Vulnerable: |
Active Bulletin Board Active Bulletin Board 1.1-beta2 Active Bulletin Board Active Bulletin Board 1.1 |
| Not Vulnerable: | |
Discussion
Active Bulletin Board Arbitrary User Password Change Vulnerability
Active Bulletin Board is prone to a vulnerability that may permit attackers to change arbitrary
passwords.
Exploiting this issue may allow an attacker to change an arbitrary user's password, bypass the authentication mechanism, and gain unauthorized access to the affected application. This may lead to other attacks.
Active Bulletin Board version 1.1 beta2 is affected by this issue.
Active Bulletin Board is prone to a vulnerability that may permit attackers to change arbitrary
passwords.
Exploiting this issue may allow an attacker to change an arbitrary user's password, bypass the authentication mechanism, and gain unauthorized access to the affected application. This may lead to other attacks.
Active Bulletin Board version 1.1 beta2 is affected by this issue.
Exploit / POC
Active Bulletin Board Arbitrary User Password Change Vulnerability
An attacker can exploit this issue via a web client.
The following exploit code is available:
An attacker can exploit this issue via a web client.
The following exploit code is available:
Solution / Fix
Active Bulletin Board Arbitrary User Password Change Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Active Bulletin Board Arbitrary User Password Change Vulnerability
References:
References:
- Active Bulletin Board (Active Bulletin Board)