CVE Vulnerabilities

CVE-2005-4453

Published: Dec 21, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

UserProfile.cs in Ultraapps Issue Manager before 2.1 allows remote authenticated users to gain administrator privileges by modifying the original (1) p_User_user_id and (2) User_user_id parameters to UserProfile.aspx, then modifying the password field.

Affected Software

Name Vendor Start Version End Version
Ultraapps_issue_manager Ultraapps 2.1 (including) 2.1 (including)

References