CVE-2009-1664
Easy Scripts Answer and Question Script - Unauthenticated Password Change via myaccount.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1664. PoCs published by InjEctOr5.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in an 'Answer and Question Script' application, along with a file upload vulnerability for remote shell execution. It includes HTML forms for uploading malicious files and changing user options.
Description
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in an 'Answer and Question Script' application, along with a file upload vulnerability for remote shell execution. It includes HTML forms for uploading malicious files and changing user options.