5
CVE-2006-0203
- EPSS 2%
- Veröffentlicht 13.01.2006 23:03:00
- Zuletzt bearbeitet 16.06.2026 22:20:05
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mini-nuke ≫ Cms System Version <= 1.8.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2% | 0.781 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html
http://secunia.com/advisories/18439
http://www.vupen.com/english/advisories/2006/0173
http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html
http://securityreason.com/securityalert/344
http://www.osvdb.org/22385
http://www.securityfocus.com/archive/1/421748/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/24101