CVE-2008-7309
05.04.2012, 13:25
Insoshi before 20080920 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the ForumPost user_id value via a modified URL, related to a "mass assignment" vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
insoshi | insoshi | 𝑥 ≤ 20080919 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration