Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-3681
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-3681

Description:
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typically for the administrator.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/44430

ST
  1020687

SREASON
  http://securityreason.com/securityalert/4157

SAID
  Secunia Advisory: SA31457

MILW0RM
  http://www.milw0rm.com/exploits/6234

CONFIRM
  http://developer.joomla.org/security/news/241-20080801-core-password-remind-functionality.html

BID
  30667


Return to the previous page.