CVE

Id
28936  
CVE No.
CVE-2007-5579  
Status
Candidate  
Description
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user"s password by calculating the confirmationcode parameter.  
Phase
Assigned (20071018)  
Votes
None (candidate not yet proposed)  
Comments