home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter. This vulnerability is addressed in the following product release:
Epic Designs, eggblog, 3.0.7
Publication date: Thu, 01 Jun 2006 15:02:00 +0000