Total vulnerabilities in the database
Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic_admin.asp.
Software | From | Fixed in |
---|---|---|
webwiz / web_wiz_forums | 7.7-a | 7.7-a.x |