Hi!! 8 years ago, I discovered this vulnerability, CVE-2010-1910, and now, you can see the details. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1910 The login page, "/sdcxuser/asp/login.asp", had a commented access to the page that allowed to change the password of any user, with a link with text "Forgot your password". The link that had the vulnerability was: "/adccommonn/asp/forgotpass.asp". You could enter any username and password without being authenticated and change it, administrator or any other user.