CVE-2008-6772
29.04.2009, 18:30
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a new account with the username of a target user.Enginsight
Vendor | Product | Version |
---|---|---|
peterselie | yourplace | 𝑥 ≤ 1.0.2 |
peterselie | yourplace | 1.0 |
peterselie | yourplace | 1.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References