Low severity3.7NVD Advisory· Published Jan 4, 2017· Updated May 6, 2026
CVE-2016-7903
CVE-2016-7903
Description
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- dotclear.org/blog/post/2016/11/01/Dotclear-2.10.3nvdPatchVendor Advisory
- hg.dotclear.org/dotclear/rev/bb06343f4247nvdPatch
- www.openwall.com/lists/oss-security/2016/10/05/5nvdMailing List
- www.securityfocus.com/bid/93439nvd
News mentions
0No linked articles in our index yet.