Security Advisory
CVE-2009-1767
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.