Security Advisory
CVE-2004-2198
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.