Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WoltLab Burning Board Predictable Account Activation String Vulnerability

WoltLab Burning Board is a free web-based bulletin board package based on PHP and MySQL.

It is possible to hijack an account that has not yet been activated. When a user creates a new account on a Burning Board forum, they will be presented with a link which they must click in order to activate their account. The link generated by Burning Board uses a predictable format which can be duplicated so that the account is activated by someone other than the user.







 

Privacy Statement
Copyright 2008, SecurityFocus