CVE-2008-7066
OpenForum 0.66 Beta - Unauthenticated Password Reset via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7066. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit targets OpenForum 0.66 Beta by leveraging session fixation and unauthorized profile updates to reset the admin password. It retrieves a session ID, then submits a crafted POST request to change the password without proper authentication.
Description
OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter set to 1 and modified user and password parameters.
Exploits (1)
This exploit targets OpenForum 0.66 Beta by leveraging session fixation and unauthorized profile updates to reset the admin password. It retrieves a session ID, then submits a crafted POST request to change the password without proper authentication.