CVE-2006-6822
Enthrallweb eClassifieds - Auth Bypass
Title source: llmDescription
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
Exploits (1)
Scores
EPSS
0.0435
EPSS Percentile
89.0%
Details
Status
published
Products (1)
enthrallweb/eclassifieds
Published
Dec 29, 2006
Tracked Since
Feb 18, 2026