CVE-2009-4674

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
05/03/2010
Last modified:
11/04/2025

Description

admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via a modified user_id field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mole-group:bus_ticket_script:-:*:*:*:*:*:*:*
cpe:2.3:a:mole-group:sky_hunter_airline_ticket_sale_script:-:*:*:*:*:*:*:*