Web Wiz Forum Multiple Vulnerabilities...

- AV AC AU C I A
发布: 2004-04-30
修订: 2025-04-13

It has been reported that Web Wiz Forum is affected by multiple vulnerabilities. These issues are due to failure to properly sanitize user-supplied input facilitating SQL injection attacks, and design errors that allow unauthorized access to certain web forum functionality. As a result of the SQL injection issue an attacker could modify the logic and structure of database queries. Other attacks may also be possible, such as gaining access to sensitive information. A design error allows any user to access the topic modification and IP address blocking scripts, permitting unauthorized users to change forum topics and block arbitrary IP addresses.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息