CVE-2006-0203

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
13/01/2006
Last modified:
19/10/2018

Description

membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mini-nuke:cms_system:*:*:*:*:*:*:*:* 1.8.2 (including)