CVE

Id
15892  
CVE No.
CVE-2005-4688  
Status
Candidate  
Description
PunBB 1.2.9 does not require password entry when changing the e-mail address in an account"s profile, which might allow an attacker to make an address change via a hijacked login session.  
Phase
Assigned (20060131)  
Votes
None (candidate not yet proposed)  
Comments