MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-05-19T04:00:00

Updated: 2024-08-08T02:19:45.940Z

Reserved: 2005-05-19T00:00:00

Link: CVE-2003-1212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2003-12-31T05:00:00.000

Modified: 2017-07-11T01:29:50.323

Link: CVE-2003-1212

cve-icon Redhat

No data.