profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
References
Link Resource
http://osvdb.org/38130 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/32035 Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/3239 Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-02-03T01:00:00

Updated: 2017-10-18T14:57:01

Reserved: 2007-02-02T00:00:00


Link: CVE-2007-0681

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2007-02-03T01:28:00.000

Modified: 2024-02-09T03:13:40.213


Link: CVE-2007-0681

JSON object: View

cve-icon Redhat Information

No data.

CWE