Vulnerabilities > CVE-2008-6473 - Credentials Management vulnerability in Blogator-Script 0.95

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
blogator-script
CWE-255
exploit available

Summary

_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.

Vulnerable Configurations

Part Description Count
Application
Blogator-Script
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionBlogator-script 0.95 Change User Password Vulnerability. CVE-2008-6473. Webapps exploit for php platform
fileexploits/php/webapps/5370.txt
idEDB-ID:5370
last seen2016-01-31
modified2008-04-05
platformphp
port
published2008-04-05
reporterVirangar Security
sourcehttps://www.exploit-db.com/download/5370/
titleBlogator-script 0.95 Change User Password Vulnerability
typewebapps