The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T19:14:47.567Z
Reserved: 2006-09-06T00:00:00
Link: CVE-2006-4586
No data.
Status : Deferred
Published: 2006-09-06T22:04:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-4586
No data.
OpenCVE Enrichment
No data.
Weaknesses