Web Wiz Forum 6.34/7.0/7.5 - Unauthorized Private Forum Access

EDB-ID:

23331




Platform:

ASP

Date:

2003-11-03


Become a Certified Penetration Tester

Enroll in Penetration Testing with Kali Linux and pass the exam to become an Offensive Security Certified Professional (OSCP). All new content for 2020.

GET CERTIFIED

source: https://www.securityfocus.com/bid/8957/info

A vulnerability has been reported in Web Wiz Forum that could allow unauthorized access to private forums. The problem occurs when handling malformed requests that make use of 'quote' mode. When this mode is used, Web Wiz Forum will allegedly fail to carry out sufficient checks between the requested forum and message. As a result, an attacker could potentially read or write to a private forum.

http://www.example.com/post_message_form.asp?mode=quote&PID=1111&FID=1&TID=11&TPN=1