Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.
| Software | From | Fixed in |
|---|---|---|
| ecartis / ecartis | 1.0.0_snapshot_2002-10-13 | 1.0.0_snapshot_2002-10-13.x |