Vulnerabilities > CVE-2008-6524 - Credentials Management vulnerability in Cale Dunlap Openinvoice

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
cale-dunlap
CWE-255
exploit available

Summary

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

Vulnerable Configurations

Part Description Count
Application
Cale_Dunlap
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionOpenInvoice 0.9 Arbitrary Change User Password Exploit. CVE-2008-6523,CVE-2008-6524. Webapps exploit for php platform
fileexploits/php/webapps/5466.pl
idEDB-ID:5466
last seen2016-01-31
modified2008-04-18
platformphp
port
published2008-04-18
reportert0pP8uZz
sourcehttps://www.exploit-db.com/download/5466/
titleOpenInvoice 0.9 - Arbitrary Change User Password Exploit
typewebapps