PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.aspapp.com/content.asp?CatId=197&ContentType=Downloads | patch |
https://www.exploit-db.com/exploits/4848 | exploit |
http://www.securityfocus.com/bid/27170 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39457 | vdb entry |
http://securityreason.com/securityalert/4439 | third party advisory |
http://secunia.com/advisories/28337 | third party advisory vendor advisory |