CVE-2005-0288

The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bottomline:webseries_payment_application:4.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=110549684319400&w=2 - () http://marc.info/?l=bugtraq&m=110549684319400&w=2 -
References () http://secunia.com/advisories/13821 - () http://secunia.com/advisories/13821 -
References () http://securitytracker.com/id?1012854 - () http://securitytracker.com/id?1012854 -
References () http://www.securityfocus.com/bid/12231 - Vendor Advisory () http://www.securityfocus.com/bid/12231 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18860 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18860 -

Information

Published : 2005-01-11 05:00

Updated : 2024-11-20 23:54


NVD link : CVE-2005-0288

Mitre link : CVE-2005-0288

CVE.ORG link : CVE-2005-0288


JSON object : View

Products Affected

bottomline

  • webseries_payment_application