|
WWWBoard Arbitrary Message Overwrite Vulnerability
wwwboard.pl is a perl script by Matt Wright, written to handle posts to a web discussion board. A problem exists in the script that allows a user to pass an input value using a <form method=POST> without checking the contents of the value. The problem occurs in the <input type=hidden name="followup" value=> field, in which the name "followup" followed by a value corresponding to a previously existing message permits one to overwrite a previously existing post to the board. Consequently, valid posts to the board can be overwritten and erased by a malcious user. |
|
|
Privacy Statement |