CVE-2008-5567 Information

Description

Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin NewPass1 and NewPass2 parameters.

Reference

http://secunia.com/advisories/33037 http://securityreason.com/securityalert/4731 https://www.exploit-db.com/exploits/7366

Share on: