Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WWWBoard Arbitrary Message Overwrite Vulnerability

wwwboard.pl is a perl script by Matt Wright, written to handle posts to a web discussion board. A problem exists in the script that allows a user to pass an input value using a <form method=POST> without checking the contents of the value. The problem occurs in the <input type=hidden name="followup" value=> field, in which the name "followup" followed by a value corresponding to a previously existing message permits one to overwrite a previously existing post to the board. Consequently, valid posts to the board can be overwritten and erased by a malcious user.







 

Privacy Statement
Copyright 2009, SecurityFocus