Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-4954

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.0%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2012-4954


Contact Us

Shodan ® - All rights reserved