CVE-2006-3398
N/A
N/A
Summary
The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.pkrinternet.com/download/RELEASE-NOTES.txt
- https://www.pkrinternet.com/taskjitsu/task/3400
- http://www.vupen.com/english/advisories/2006/2660
References
- http://www.pkrinternet.com/download/RELEASE-NOTES.txt
- https://www.pkrinternet.com/taskjitsu/task/3400
- http://www.vupen.com/english/advisories/2006/2660
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.