Description: A vulnerability has been reported in Geeklog allowing malicious users to manipulate SQL queries.
A specific issue has been reported allowing malicious users to change the password for arbitrary users. This can be done by manipulating the "reqid" parameter when updating passwords.
The vulnerability has been reported in version 1.3.8.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.