5
CVSSv2

CVE-2009-1767

Published: 22/05/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote malicious users to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

2daybiz template monster clone -

Exploits

<title> Template Monster Clone Change Password </title> </head> <head> </head> <body bgcolor="#000000"> <p><font size="6" color="#FF0000"><a href="www2daybizcom/"> <font color="#FF0000">2daybiz</font></a> Template Monster Clone  </font>& ...