PT-2005-3490 · Fudforum · Fudforum

Alexander Heidenreich

·

Publicado

2005-08-17

·

Atualizado

2008-09-05

·

CVE-2005-2600

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FUDForum version 2.6.15
Description The issue allows remote attackers to read private posts. This is achieved by modifying the mid parameter. The problem is specifically noted in configurations where the "Tree View" is enabled, a setup also found in other products.
Recommendations For FUDForum version 2.6.15, consider disabling the "Tree View" feature as a temporary workaround until a patch is available. Restrict access to private posts to minimize the risk of exploitation. Avoid using the modified mid parameter in affected configurations until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2600
DSA-798-1
DSA-899-1

Produtos afetados

Fudforum