|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Allaire Forums 2.0.5 may allow users to view, and post to secure conferences through unsecure conferences or via email, because of improper handling of the "rightAccessAllForums" variable.
|
|
Classification |
Unknown or Incomplete
|
|
Technical |
The "rightAccessAllForums" variable is not scoped properly in the Forums code, which allows remote attackers to post to and view conferences they are not part of, and allows them to sign up for conferences that have not been created yet.
|
|
Solution |
To fix resolve this vulnerability, install the Allaire Forums 2.0.5 Security Patch or upgrade to Allaire Forums version 2.0.6 or higher. However, if upgrading is not possible, remove the following template files (this may break some Forums functionality): Application.cfm, Conf_ThreadList.cfm, MessageEdit_Action.cfm, Search_Results.cfm, _NewSession.cfm
|
|
Products |
|
Forums
 |
2.0.5 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|