20000106 Phorum 3.0.7 exploits and IDS signaturesmailing list
http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html CVE-2000-1228
Phorum 3.0.7 - 'admin.php3' Unverified Administrative Password Change
Record summary
CVE-2000-1228 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPhorum 3.0.7 - 'admin.php3' Unverified Administrative Password ChangeExploitDB exploitby Max VisionNot analyzed1 file
References
5hispahack.ccc.de
http://hispahack.ccc.de/mi020.html digitalsec.net
http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm 2271vdb entry
http://www.securityfocus.com/bid/2271 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1228