PT-2003-2128 · Web Wiz · Web Wiz Forums

Publicado

2003-12-31

·

Atualizado

2017-07-11

·

CVE-2003-1176

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Web Wiz Forums versions 6.34 through 7.5
Description The issue allows remote attackers to access private forums without authorization. This is achieved by modifying the FID (forum ID) parameter in the quote mode of the post message form.asp file.
Recommendations For Web Wiz Forums versions 6.34 through 7.5, avoid using the quote mode until a patch is available. As a temporary workaround, consider restricting access to the post message form.asp file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1176

Produtos afetados

Web Wiz Forums