The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.
References
Configurations
History
No history.
Information
Published : 2005-01-11 05:00
Updated : 2017-07-11 01:32
NVD link : CVE-2005-0288
Mitre link : CVE-2005-0288
CVE.ORG link : CVE-2005-0288
JSON object : View
Products Affected
bottomline
- webseries_payment_application
CWE