PT-2002-1194 · Foru Cms+1 · Foru Cms+1

Publicado

2002-03-15

·

Atualizado

2008-11-04

·

CVE-2002-0108

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Allaire Forums versions 2.0.4 through 2.0.5 Forums! versions 3.0 through 3.1
Description The issue allows remote authenticated users to spoof messages as other users. This is achieved by modifying the hidden form fields for the name and e-mail address.
Recommendations For Allaire Forums versions 2.0.4 through 2.0.5, consider restricting access to the form fields until a fix is available. For Forums! versions 3.0 through 3.1, avoid using the hidden form fields for user identification until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0108

Produtos afetados

Allaire Forums
Foru Cms