post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Web_wiz_forums | Bdc_enterprises | 6.34 (including) | 6.34 (including) |
| Web_wiz_forums | Bdc_enterprises | 7.01 (including) | 7.01 (including) |
| Web_wiz_forums | Bdc_enterprises | 7.5 (including) | 7.5 (including) |