Vulnerabilities > CVE-2007-5579 - Credentials Management vulnerability in Pligg CMS 9.5

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
pligg
CWE-255
exploit available

Summary

login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's password by calculating the confirmationcode parameter.

Vulnerable Configurations

Part Description Count
Application
Pligg
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionPligg 9.5 Reset Forgotten Password Security Bypass Vulnerability. CVE-2007-5579. Webapps exploit for php platform
idEDB-ID:30088
last seen2016-02-03
modified2007-05-25
published2007-05-25
reporter242th section
sourcehttps://www.exploit-db.com/download/30088/
titlePligg 9.5 Reset Forgotten Password Security Bypass Vulnerability