Description
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-5335 Vulnerability (CVE-2006-5335)
WordPress Plugin Easy Filter SQL Injection (1.5)
WordPress Plugin WP Prayer Cross-Site Request Forgery (1.5.4)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1607)
Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2969)