The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:21

Updated: 2022-10-03T16:21:21

Reserved: 2022-10-03T00:00:00


Link: CVE-2006-6588

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2006-12-15T19:28:00.000

Modified: 2019-07-17T17:46:57.460


Link: CVE-2006-6588

JSON object: View

cve-icon Redhat Information

No data.