Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2198
CVE-2004-2198
Description
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
Affected products
2cpe:2.3:a:duware:duclassmate:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:duware:duclassmate:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:duware:duclassmate:1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/11363nvdExploit
- www.securitytracker.com/alerts/2004/Oct/1011597.htmlnvdExploitVendor Advisory
- www.osvdb.org/10663nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17682nvd
News mentions
0No linked articles in our index yet.