WoltLab Burning Board Predictable Account Activation String Vulnerability
BID:4859
Info
WoltLab Burning Board Predictable Account Activation String Vulnerability
| Bugtraq ID: | 4859 |
| Class: | Design Error |
| CVE: |
CVE-2002-0903 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovery is credited to SeazoN <[email protected]>. |
| Vulnerable: |
Woltlab Burning Board 1.1.1 |
| Not Vulnerable: | |
Discussion
WoltLab Burning Board Predictable Account Activation String Vulnerability
WoltLab Burning Board is a free web-based bulletin board package based on PHP and MySQL.
It is possible to hijack an account that has not yet been activated. When a user creates a new account on a Burning Board forum, they will be presented with a link which they must click in order to activate their account. The link generated by Burning Board uses a predictable format which can be duplicated so that the account is activated by someone other than the user.
WoltLab Burning Board is a free web-based bulletin board package based on PHP and MySQL.
It is possible to hijack an account that has not yet been activated. When a user creates a new account on a Burning Board forum, they will be presented with a link which they must click in order to activate their account. The link generated by Burning Board uses a predictable format which can be duplicated so that the account is activated by someone other than the user.
Exploit / POC
WoltLab Burning Board Predictable Account Activation String Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
WoltLab Burning Board Predictable Account Activation String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WoltLab Burning Board Predictable Account Activation String Vulnerability
References:
References:
- CityForFree Product Page (CityForFree)