CVE-2006-2807
ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.06% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- aspwebsoft/speedy asp discussion forum
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/1037
- http://www.securityfocus.com/archive/1/435209/100/0/threaded
- http://www.securityfocus.com/bid/18170Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26811
- http://securityreason.com/securityalert/1037
- http://www.securityfocus.com/archive/1/435209/100/0/threaded
- http://www.securityfocus.com/bid/18170Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26811
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.