member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-08-12T10:00:00

Updated: 2017-09-28T12:57:01

Reserved: 2009-08-11T00:00:00


Link: CVE-2008-6957

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-08-12T10:30:00.983

Modified: 2017-09-29T01:33:27.043


Link: CVE-2008-6957

JSON object: View

cve-icon Redhat Information

No data.

CWE