CVE-2010-3713 Information

Description

rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.

Reference

http://www.openwall.com/lists/oss-security/2010/10/08/5 http://www.openwall.com/lists/oss-security/2010/10/11/5 http://www.usebb.net/community/topic.php?id=2501 http://www.usebb.net/community/topic-2495.html

Share on: