The new thread posting page in APBoard 2.02 and 2.03 allows remote attackers to post messages to protected forums by modifying the insertinto parameter.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/1/299536 | mailing list exploit |
http://www.securityfocus.com/bid/6167 | vdb entry |
http://www.iss.net/security_center/static/10611.php | vdb entry |
http://securityreason.com/securityalert/3332 | third party advisory exploit |