Vulnerabilities > CVE-2008-5670 - Credentials Management vulnerability in Textpattern 4.0.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- http://secunia.com/advisories/28793
- http://secunia.com/advisories/28793
- http://securityreason.com/securityalert/4786
- http://securityreason.com/securityalert/4786
- http://www.securityfocus.com/archive/1/487483/100/200/threaded
- http://www.securityfocus.com/archive/1/487483/100/200/threaded
- http://www.securityfocus.com/bid/27606
- http://www.securityfocus.com/bid/27606