BugTraq
Re: Unauthorized access in Web Wiz Forum Nov 04 2003 11:15AM
bruce webwizguide info
In-Reply-To: <020a01c3a126$9b91aaf0$0bd3bdd5@pigkiller>

The following issue has been resolved with release 7.51 of Web Wiz Forums.

The updated version, 7.51, that has corrected this vulnerability can be downloaded from:-

http://www.webwizforums.com

>

>

>Unauthorized access in Web Wiz Forum

>

>A vulnerability has found in Web Wiz Forum (6.34, 7.01, 7.5). Remote user

>(authenticated or not) can read message in private forum. Remote user can

>post message in private forum.

>

>Software does not compare message to forum, when "quote" mode is used. In

>result, remote user (authenticated or not) can read and post message in

>private forum, to which he hasn't access.

>

>thanks to Tecklord, Pharaoh and other moderator of

>http://Forum.SecurityLab.ru

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus