MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-05-19T04:00:00
Updated: 2017-07-10T14:57:01
Reserved: 2005-05-19T00:00:00
Link: CVE-2003-1212
JSON object: View
NVD Information
Status : Modified
Published: 2003-12-31T05:00:00.000
Modified: 2017-07-11T01:29:50.323
Link: CVE-2003-1212
JSON object: View
Redhat Information
No data.
CWE