Vulnerabilities > CVE-2004-2198 - Remote vulnerability in DUware Software
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | DUclassmate 1.x account.asp MM-recordId Parameter Arbitrary Password Modification. CVE-2004-2198. Webapps exploit for asp platform |
id | EDB-ID:24672 |
last seen | 2016-02-02 |
modified | 2004-10-11 |
published | 2004-10-11 |
reporter | Soroosh Dalili |
source | https://www.exploit-db.com/download/24672/ |
title | DUclassmate 1.x account.asp MM-recordId Parameter Arbitrary Password Modification |
Nessus
NASL family | CGI abuses |
NASL id | DUWARE_MULTIPLE_FLAWS.NASL |
description | The remote host is running a product published by DUware - either DUclassmate, DUclassified or DUforum. There is a flaw in the remote version of this software that could allow an attacker to execute arbitrary SQL statements on the remote host by supplying malformed values to the arguments of /admin/, messages.asp or messagesDetails.asp. In addition, DUclassified contains a cross-site scripting vulnerability in Message Text handling. DUclassmate contains an unauthorized password manipulation issue in account.asp. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15453 |
published | 2004-10-11 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15453 |
title | DUware Products Multiple Remote Vulnerabilities (SQLi, XSS) |
code |
|