CVE-2008-7155
NetRisk 1.9.7 - Info Disclosure
Title source: llmDescription
NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of arbitrary users via a direct request.
Exploits (1)
Scores
EPSS
0.0129
EPSS Percentile
79.7%
Details
CWE
CWE-264
Status
published
Products (1)
phprisk/netrisk
1.9.7
Published
Sep 02, 2009
Tracked Since
Feb 18, 2026