Vulnerabilities > CVE-2006-6822 - Products Myprofile.ASP Arbitrary User Password Change vulnerability in EnthrallWeb

047910
CVSS 3.5 - LOW
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
enthrallweb
exploit available

Summary

myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

Vulnerable Configurations

Part Description Count
Application
Enthrallweb
1

Exploit-Db

descriptionEnthrallweb eClassifieds 1.0 Remote User Pass Change Exploit. CVE-2006-6822. Webapps exploit for asp platform
fileexploits/asp/webapps/2994.html
idEDB-ID:2994
last seen2016-01-31
modified2006-12-23
platformasp
port
published2006-12-23
reporterajann
sourcehttps://www.exploit-db.com/download/2994/
titleEnthrallweb eClassifieds 1.0 - Remote User Pass Change Exploit
typewebapps