CVE-2004-2733

Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic_admin.asp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webwiz:web_wiz_forums:7.7:a:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2004-04/1119.html - () http://archives.neohapsis.com/archives/fulldisclosure/2004-04/1119.html -
References () http://secunia.com/advisories/11525 - Vendor Advisory () http://secunia.com/advisories/11525 - Vendor Advisory
References () http://securitytracker.com/id?1010012 - () http://securitytracker.com/id?1010012 -
References () http://www.osvdb.org/5750 - () http://www.osvdb.org/5750 -
References () http://www.osvdb.org/5751 - () http://www.osvdb.org/5751 -
References () http://www.securityfocus.com/bid/10255 - () http://www.securityfocus.com/bid/10255 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16030 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16030 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16031 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16031 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:54


NVD link : CVE-2004-2733

Mitre link : CVE-2004-2733

CVE.ORG link : CVE-2004-2733


JSON object : View

Products Affected

webwiz

  • web_wiz_forums
CWE
CWE-264

Permissions, Privileges, and Access Controls