peter bassill · operator
$ cve CVE-2008-6957 JSON

CVE-2008-6957 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.84% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-08-12
Last modified2026-06-16

Affected (1)

VendorProduct
discuzdiscuz\!

Public exploits

SourceTitleDate
exploit-dbDiscuz! - Remote Reset User Password2008-11-22

References

→ the Explorer  ·  watch your stack  ·  NVD