|
WoltLab Burning Board Predictable Account Activation String Vulnerability
WoltLab Burning Board is a free web-based bulletin board package based on PHP and MySQL. It is possible to hijack an account that has not yet been activated. When a user creates a new account on a Burning Board forum, they will be presented with a link which they must click in order to activate their account. The link generated by Burning Board uses a predictable format which can be duplicated so that the account is activated by someone other than the user. |
|
|
Privacy Statement |