PT-2002-1194 · Foru Cms+1 · Foru Cms+1

Published

2002-03-15

·

Updated

2008-11-04

·

CVE-2002-0108

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Allaire Forums versions 2.0.4 through 2.0.5 Forums! versions 3.0 through 3.1
Description The issue allows remote authenticated users to spoof messages as other users. This is achieved by modifying the hidden form fields for the name and e-mail address.
Recommendations For Allaire Forums versions 2.0.4 through 2.0.5, consider restricting access to the form fields until a fix is available. For Forums! versions 3.0 through 3.1, avoid using the hidden form fields for user identification until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0108

Affected Products

Allaire Forums
Foru Cms