7.5
CVSSv2

CVE-2008-3681

Published: 14/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

components/com_user/models/reset.php in Joomla! 1.5 up to and including 1.5.5 does not properly validate reset tokens, which allows remote malicious users to reset the "first enabled user (lowest id)" password, typically for the administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joomla com user 1.5.1

joomla com user 1.5.2

joomla com user 1.5.3

joomla com user 1.5.4

joomla com user 1.5

joomla com user 1.5.5

Exploits

##################################################################################### #### Joomla 15x Remote Admin Password Change #### ##################################################################################### # # # Auth ...