6.8
CVSSv2

CVE-2008-6729

Published: 20/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and previous versions allow remote malicious users to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email_address parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmotion phpmotion 2.0

phpmotion phpmotion 1.0

phpmotion phpmotion

Exploits

PHPmotion <= 21 CSRF vulnerability Author: Ausome1 Email: Ausorme1@gmailcom Website: wwwenigmagrouporg Description: Change a member's password and/or email --------------------------------------------------------------------------------------------------- Social engineer a PHPMotion member to come to your web page with the followi ...