CVE

Id
2265  
CVE No.
CVE-2000-0689  
Status
Candidate  
Description
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.  
Phase
Modified (20061027)  
Votes
ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  
Comments
Frech> XF:account-manager-overwrite-password | In description, you probably want to indicate both Account Manager LITE and PRO. | Because CONFIRM redirects, you may want to verify and normalize to http://www.cgiscriptcenter.com/acctman/index2.html. | Christey> XF:account-manager-overwrite-password | http://xforce.iss.net/static/5125.php | Frech> XF:account-manager-overwrite-password(5125)