Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic_admin.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_wiz_forums | Webwiz | 7.7-a (including) | 7.7-a (including) |