Vulnerabilities > CVE-2006-2807 - Unspecified vulnerability in Aspwebsoft Speedy ASP Discussion Forum
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN aspwebsoft
exploit available
Summary
ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Speedy ASP Forum (profileupdate.asp) User Pass Change Exploit. CVE-2006-2807. Webapps exploit for asp platform |
id | EDB-ID:1849 |
last seen | 2016-01-31 |
modified | 2006-05-29 |
published | 2006-05-29 |
reporter | ajann |
source | https://www.exploit-db.com/download/1849/ |
title | Speedy ASP Forum profileupdate.asp User Pass Change Exploit |
References
- http://securityreason.com/securityalert/1037
- http://securityreason.com/securityalert/1037
- http://www.securityfocus.com/archive/1/435209/100/0/threaded
- http://www.securityfocus.com/archive/1/435209/100/0/threaded
- http://www.securityfocus.com/bid/18170
- http://www.securityfocus.com/bid/18170
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26811
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26811