CVE-2009-4851
N/A
N/A
Summary
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://secunia.com/advisories/37274
- http://www.xoops.org/modules/news/article.php?storyid=5096
- http://www.xoops.org/modules/newbb/viewtopic.php?post_id=319132
- http://www.vupen.com/english/advisories/2009/3256
References
- http://secunia.com/advisories/37274
- http://www.xoops.org/modules/news/article.php?storyid=5096
- http://www.xoops.org/modules/newbb/viewtopic.php?post_id=319132
- http://www.vupen.com/english/advisories/2009/3256
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.