CVE-2009-1767 Information

Description

admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication which allows remote attackers to modify arbitrary accounts via the (1) loginname (2) password (3) email (4) firstname or (5) lastname parameter.

Reference

http://secunia.com/advisories/35090 http://www.securityfocus.com/bid/34977 https://exchange.xforce.ibmcloud.com/vulnerabilities/50561 https://www.exploit-db.com/exploits/8691

Share on: