APBoard Unauthorized Thread Reading Vulnerability
BID:6330
Info
APBoard Unauthorized Thread Reading Vulnerability
| Bugtraq ID: | 6330 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2002 12:00AM |
| Updated: | Dec 06 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to DNA ESC <[email protected]>. |
| Vulnerable: |
APP APBoard 2.0 2 |
| Not Vulnerable: | |
Discussion
APBoard Unauthorized Thread Reading Vulnerability
A vulnerability has been reported for APBoard that may allow unauthorized users to read postings in internal forums. The vulnerability is a result of the 'useraction.php' script failing to properly check user credentials.
A vulnerability has been reported for APBoard that may allow unauthorized users to read postings in internal forums. The vulnerability is a result of the 'useraction.php' script failing to properly check user credentials.
Exploit / POC
APBoard Unauthorized Thread Reading Vulnerability
The following proof of concept was provided:
www.board.de/useraction.php3?action=subscribe_thread&threadid=<private thread id>
The following proof of concept was provided:
www.board.de/useraction.php3?action=subscribe_thread&threadid=<private thread id>
Solution / Fix
APBoard Unauthorized Thread Reading Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.