Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-2807. PoCs published by ajann.
AI-analyzed exploit summary This HTML form exploits CVE-2006-2807, a vulnerability in Speedy Forum that allows unauthorized password changes by submitting crafted POST requests to profileupdate.asp. The exploit leverages insufficient authentication checks to modify user credentials.
Description
ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp.
Exploits (1)
This HTML form exploits CVE-2006-2807, a vulnerability in Speedy Forum that allows unauthorized password changes by submitting crafted POST requests to profileupdate.asp. The exploit leverages insufficient authentication checks to modify user credentials.