The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-6571 | The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://issues.apache.org/jira/browse/OFBIZ-178 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T19:41:40.430Z
Reserved: 2006-12-15T00:00:00Z
Link: CVE-2006-6588
No data.
Status : Deferred
Published: 2006-12-15T19:28:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2006-6588
No data.
OpenCVE Enrichment
No data.
EUVD