PT-2006-3647 · Eggblog · Eggblog

Mustafa Can Bjorn Ipekci

+1

·

Published

2006-06-01

·

Updated

2018-10-18

·

CVE-2006-2727

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Eggblog versions prior to 3.0
Description The issue allows remote attackers to change the password of administrators and possibly other users. This is achieved by modifying the username parameter in the 'home/register.php' endpoint.
Recommendations For Eggblog versions prior to 3.0, consider restricting access to the 'home/register.php' endpoint until a fix is available. As a temporary workaround, avoid using the username parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2727

Affected Products

Eggblog