Security holes in Powerboard forum

From: frog frog (leseulfrogat_private)
Date: Tue Apr 09 2002 - 03:10:43 PDT

  • Next message: circut: "Re: Studying buffer overflows [maybe OT]"

    
     ('binary' encoding is not supported, stored as-is)
    Product :
    Powerboards
    http://powerboards.sourceforge.net/
    
    Versions :
    2.2b (and less ?)
    
    Problems :
    - Cross Site Scripting
    - Path disclosure
    - Access to the administration
    - Access to users accounts without password
    - Recovery  of admins/users passwords
    - Suppression of messages
    - Writing on the hard disk
    
    More details :
    in french :
    http://www.ifrance.com/kitetoua/tuto/powerboards.txt
    
    translated by Google :
    http://translate.google.com/translate?u=http%3A%
    2F%2Fwww.ifrance.com%2Fkitetoua%2Ftuto%
    2Fpowerboards.txt&langpair=fr%7Cen&hl=fr&prev=%
    2Flanguage_tools
    
    
    frog-m@n
    



    This archive was generated by hypermail 2b30 : Tue Apr 09 2002 - 09:10:54 PDT