CVE

Id
25321  
CVE No.
CVE-2007-1964  
Status
Candidate  
Description
member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account"s registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.  
Phase
Assigned (20070410)  
Votes
None (candidate not yet proposed)  
Comments