Forums! Insecure User Validation Message Posting Vulnerability
BID:3827
Info
Forums! Insecure User Validation Message Posting Vulnerability
| Bugtraq ID: | 3827 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0108 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Posted to the BugTraq mailing list by John Cantu <[email protected]> on January 8, 2002. |
| Vulnerable: |
Forums! Forums! 3.1 Forums! Forums! 3.0 Allaire Forums 2.0.5 Allaire Forums 2.0.4 |
| Not Vulnerable: | |
Discussion
Forums! Insecure User Validation Message Posting Vulnerability
Forums! is a web based bulletin board system which uses the Allaire Cold Fusion server backend. Forums! is derived from the open source release of the Allaire Forums software.
A vulnerability exists in the way new messages are posted. The identity of the sender of a message is determined from values supplied as CGI parameters, passed through hidden form fields. These values may be trivially changed by a user of the system, resulting in the impersonation of another valid user.
Allaire Forums shares this vulnerability.
It is unknown whether an account on the Forums! system is required in order to exploit this vulnerability.
Forums! is a web based bulletin board system which uses the Allaire Cold Fusion server backend. Forums! is derived from the open source release of the Allaire Forums software.
A vulnerability exists in the way new messages are posted. The identity of the sender of a message is determined from values supplied as CGI parameters, passed through hidden form fields. These values may be trivially changed by a user of the system, resulting in the impersonation of another valid user.
Allaire Forums shares this vulnerability.
It is unknown whether an account on the Forums! system is required in order to exploit this vulnerability.
Exploit / POC
Forums! Insecure User Validation Message Posting Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
Forums! Insecure User Validation Message Posting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Forums! Insecure User Validation Message Posting Vulnerability
References:
References:
- Forums 2.0 Product Homepage (Allaire)