VulnAware.com

Bringing security awareness to the masses

CVE-2009-4674 (buss_ticket_script, sky_hunter_airline_ticket_sale_script)

admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via a modified user_id field.

Comments are closed.