32731Third-party advisory
http://secunia.com/advisories/32731 CVE-2008-6957
Discuz! - Remote Reset User Password
Record summary
CVE-2008-6957 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDiscuz! - Remote Reset User PasswordExploitDB exploitby 80vulNot analyzed1 file
References
780vul.com
http://www.80vul.com/dzvul/sodb/14/dz-exp-sodb-2008-14_php.htm discuz.net
http://www.discuz.net/archiver?tid-1112426.html 32424vdb entry
http://www.securityfocus.com/bid/32424 discuz-member-security-bypass(46785)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/46785 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6957 7185exploit
https://www.exploit-db.com/exploits/7185