CVE-2008-6957

Crossday Discuz! Board - Unauthenticated Password Reset via Predictable ID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6957. PoCs published by 80vul.

AI-analyzed exploit summary This exploit targets a password reset vulnerability in Discuz! by leveraging a weak random seed to predict the reset token. It automates the process of resetting a user's password to '123456' without proper authorization.

Description

member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by 80vul · phpwebappsphp
https://www.exploit-db.com/exploits/7185

This exploit targets a password reset vulnerability in Discuz! by leveraging a weak random seed to predict the reset token. It automates the process of resetting a user's password to '123456' without proper authorization.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Discuz! (version not specified, likely older versions)
No auth needed
Prerequisites: Target Discuz! installation · Valid username, email, and UID of the target user · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7185
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32731
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46785
Vendor Advisory x_refsource_misc
http://www.discuz.net/archiver/?tid-1112426.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32424

Scores

EPSS 0.0284
EPSS Percentile 84.9%

Details

CWE
CWE-264
Status published
Products (1)
discuz/discuz\!
Published Aug 12, 2009
Tracked Since Feb 18, 2026