JobScript 'changepassword.php' Remote Password Change Vulnerability

JobScript is prone to a vulnerability that may permit an attacker to change the password of arbitrary users.

Exploiting this issue may allow the attacker to gain unauthorized access to the affected application. Successful exploits will completely compromise victims' accounts.

JobScript 2.0 is vulnerable; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus