Security holes in Powerboard forum

From: frog frog (leseulfrog@hotmail.com)
Date: Tue Apr 09 2002 - 06:10:43 EDT


('binary' encoding is not supported, stored as-is) Product :
Powerboards
http://powerboards.sourceforge.net/

Versions :
2.2b (and less ?)

Problems :
- Cross Site Scripting
- Path disclosure
- Access to the administration
- Access to users accounts without password
- Recovery of admins/users passwords
- Suppression of messages
- Writing on the hard disk

More details :
in french :
http://www.ifrance.com/kitetoua/tuto/powerboards.txt

translated by Google :
http://translate.google.com/translate?u=http%3A%
2F%2Fwww.ifrance.com%2Fkitetoua%2Ftuto%
2Fpowerboards.txt&langpair=fr%7Cen&hl=fr&prev=%
2Flanguage_tools

frog-m@n



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 22:28:03 EDT