Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » APBoard-Bug

APBoard-Bug

by Nikola Strahija on December 7th, 2002 Versions: tested on 2.02


Introduction:
Normal Users can read new answers to a thread in the internal forum
I have already informed APP about this vulnerability!

Exploit:

1.) register an account on vuln board

2.) while the number of the threads from the intern board were seen in the public board , everybody can see when a new thrad were created

3.) You are able to get the thread-id of the last created thread in the internal form by increasing the last public threadid by one.(you may find it by searching + sort by date)

4.) Using the link

www.board.de/useraction.php3?action=subscribe_thread&threadid=

it is possible to subscribe an internal thread whose replies will be sent to you by email automatically.
------------------

for example: (in case of threadid=990)

www.board.de/useraction.php3?action=subscribe_thread&threadid=990

"useraction.php" does no test whether the subscription is allowed or not, so an unauthorized
person is able to read the replies he was sent, which eleminates the intention of the
internal forums' existance.


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »