_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified a parameter with a % wildcard symbol in the b parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Blogator-script | Blogator-script | 0.95 (including) | 0.95 (including) |