Unrated severityNVD Advisory· Published Sep 6, 2006· Updated Apr 16, 2026
CVE-2006-4586
CVE-2006-4586
Description
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- acid-root.new.fr/poc/10060903.txtnvdExploit
- www.securityfocus.com/bid/19834nvdExploit
- secunia.com/advisories/21754nvdVendor Advisory
- securityreason.com/securityalert/1508nvd
- securitytracker.com/idnvd
- www.osvdb.org/28542nvd
- www.securityfocus.com/archive/1/445079/100/0/threadednvd
- www.vupen.com/english/advisories/2006/3452nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28756nvd
- www.exploit-db.com/exploits/2297nvd
News mentions
0No linked articles in our index yet.