Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6547 (RunCMS)

BugsAlert Home > CVE-2007-6547 (RunCMS)
 
 

RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6547

Learn more about CVE-2007-6547 (RunCMS)
 
Tags: cve-2007-6547 runcms

Related Items

      SUSE update for postgresql

      CVE-2007-5960 (Firefox, SeaMonkey)

      BitTorrent Peer Client Denial of Service Vulnerability

      Yerba SACphp Multiple Vulnerabilities

      WORM_DELF.NAT

      CVE-2008-3169 (Empire Server)

      FrSIRT - Novell GroupWise Windows Client API Security Bypass Vulnerability

 

Pixel