Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic_admin.asp.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://securitytracker.com/id?1010012 | vdb entry |
http://www.osvdb.org/5751 | vdb entry |
http://www.securityfocus.com/bid/10255 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16030 | vdb entry |
http://secunia.com/advisories/11525 | third party advisory vendor advisory |
http://www.osvdb.org/5750 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16031 | vdb entry |
http://archives.neohapsis.com/archives/fulldisclosure/2004-04/1119.html | mailing list |