CVE-2006-6821
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a…
Does this matter?
Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.
Description
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- enthrallweb/enews
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23518Vendor Advisory
- http://www.securityfocus.com/bid/21739
- http://www.vupen.com/english/advisories/2006/5156
- https://www.exploit-db.com/exploits/2996
- http://secunia.com/advisories/23518Vendor Advisory
- http://www.securityfocus.com/bid/21739
- http://www.vupen.com/english/advisories/2006/5156
- https://www.exploit-db.com/exploits/2996
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.