2008-10-03 22:00:00
mitre
PUBLISHED
changepassword.php in Phlatlines Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.