First published: Fri Dec 15 2006(Updated: )
The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OFBiz |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.