Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.
https://exchange.xforce.ibmcloud.com/vulnerabilities/11431
http://www.securityfocus.com/bid/6971
http://www.debian.org/security/2003/dsa-271