mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 00:28:04 +02:00
18 lines
710 B
Markdown
18 lines
710 B
Markdown
### [CVE-2009-1767](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1767)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.exploit-db.com/exploits/8691
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|