links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.
https://www.exploit-db.com/exploits/1859
http://www.securityfocus.com/archive/1/435735/100/0/threaded