CVE-2010-3273 Information
Feb 14, 2021
cve
Description
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords and consequently obtain access to arbitrary user accounts by providing a user id to accounts/ValidateUser and then providing a new password to accounts/ResetResult.
Reference
http://secunia.com/advisories/43241 http://securityreason.com/securityalert/8089 http://www.coresecurity.com/content/zoho-manageengine-vulnerabilities http://www.osvdb.org/70869 http://www.securityfocus.com/archive/1/516396/100/0/threaded http://www.securityfocus.com/bid/46331 http://www.vupen.com/english/advisories/2011/0392 https://exchange.xforce.ibmcloud.com/vulnerabilities/65348
Share on: