The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real names, which makes it easier for remote authenticated users to impersonate other users.
                
            References
                    Configurations
                    History
                    21 Nov 2024, 00:33
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://osvdb.org/45399 - | |
| References | () http://www.web-app.org/cgi-bin/index.cgi?action=forum&board=how_to&op=display&num=9458 - | |
| References | () http://www.web-app.org/downloads/WebAPPv0.9.9.7.zip - Patch | 
Information
                Published : 2007-06-26 23:30
Updated : 2025-04-09 00:30
NVD link : CVE-2007-3418
Mitre link : CVE-2007-3418
CVE.ORG link : CVE-2007-3418
JSON object : View
Products Affected
                web-app.org
- webapp
CWE
                