6.4
CVSSv2

CVE-2004-2198

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

account.asp in DUware DUclassmate 1.0 up to and including 1.1 allows remote malicious users to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.

Vulnerable Product Search on Vulmon Subscribe to Product

duware duclassmate 1.1

duware duclassmate 1.0

Exploits

source: wwwsecurityfocuscom/bid/11363/info Multiple vulnerabilities have been identified in the software that may allow a remote attacker to carry out SQL injection and HTML injection attacks An attacker may also gain unauthorized access to a user's account DUclassmate may allow unauthorized remote attackers to gain access to a compu ...