Описание
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.
Ссылки
- Vendor Advisory
- Exploit
- Vendor Advisory
- Exploit
- Vendor Advisory
- Exploit
- Vendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:discuz:discuz\!:-:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06677
Низкий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.
EPSS
Процентиль: 91%
0.06677
Низкий
7.5 High
CVSS2
Дефекты
CWE-264