<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : &#146;Move posts&#146; security bug</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : &#146;Move posts&#146; security bug]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Mon, 13 Apr 2026 21:12:59 +0000</pubDate>
  <lastBuildDate>Sat, 13 Aug 2005 01:40:30 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=13879</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[&#146;Move posts&#146; security bug : I have similar problem as pedalcars,...]]></title>
   <link>https://forums.webwiz.net/move-posts-security-bug_topic13879_post88693.html#88693</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=20368">mantey</a><br /><strong>Subject:</strong> 13879<br /><strong>Posted:</strong> 13&nbsp;August&nbsp;2005 at 1:40am<br /><br /><DIV>I have similar problem as pedalcars, but I don't care if some moderator&nbsp;move the topic from his forum to the forum which is not normaly visible to him. I just don't want the moderator can see the list of topics in the hidden forum.</DIV><DIV>&nbsp;</DIV><DIV>Maybe it would be nice&nbsp;to prevent only the possibility of moderator to view the topics of hidden forum when using the move post option. For example. If moderator choose the hidden forum&nbsp;(hidden to him) into which he want to put some message from "his" forum, then in page move_post_form_to.asp the list of all the topics in hidden forum will not be shown, and he will have the possibility only to make a&nbsp;new topic.</DIV><DIV>&nbsp;</DIV><DIV>Is there any mod to make that possible.</DIV>]]>
   </description>
   <pubDate>Sat, 13 Aug 2005 01:40:30 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/move-posts-security-bug_topic13879_post88693.html#88693</guid>
  </item> 
  <item>
   <title><![CDATA[&#146;Move posts&#146; security bug :   -boRg- wrote:The moving of...]]></title>
   <link>https://forums.webwiz.net/move-posts-security-bug_topic13879_post76625.html#76625</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=4643">pedalcars</a><br /><strong>Subject:</strong> 13879<br /><strong>Posted:</strong> 18&nbsp;February&nbsp;2005 at 8:38am<br /><br /> <table width="99%"><tr><td class="BBquote"><img src="forum_images/quote_box.png" title="Originally posted by -boRg-" alt="Originally posted by -boRg-" style="vertical-align: text-bottom;" /> <strong>-boRg- wrote:</strong><br /><br />The moving of posts by moderators between forums allows moderators to move posts to forums they are not moderators in</td></tr></table> <br /><br />That's fine - but moving a post to a forum for which a person isn't a moderator is not the problem (I can see why that could be useful), it's that a moderator can move a post into a forum that normally he cannot see or access.<br /><br />I accept it would reduce performance (slightly), but if, for example, the drop-down list of destinations to move a post to was filtered as the forum default page is, to only display the forums to which the moderator has (at least read) access, that would do.<br /><br />Certainly in our case, it's highly unlikely that anyone will have access to two areas *and* that the moderator of one will be completely excluded from the other.<br /><br />Maybe other users will have different opinions.]]>
   </description>
   <pubDate>Fri, 18 Feb 2005 08:38:21 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/move-posts-security-bug_topic13879_post76625.html#76625</guid>
  </item> 
  <item>
   <title><![CDATA[&#146;Move posts&#146; security bug : This isn&amp;#039;t so much a case...]]></title>
   <link>https://forums.webwiz.net/move-posts-security-bug_topic13879_post76622.html#76622</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 13879<br /><strong>Posted:</strong> 18&nbsp;February&nbsp;2005 at 8:21am<br /><br />This isn't so much a case of security but one of security verses functionality.<br><br>The moving of posts by moderators between forums allows moderators tomove posts to forums they are not moderators in, which in many cases isuseful and a required function.<br><br>So this should more be a question of would people like to keep thislevel of functionality in the next version, or would they like to havetighter security restricting moderators from moving posts to forums theyare not moderators in?<br>]]>
   </description>
   <pubDate>Fri, 18 Feb 2005 08:21:36 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/move-posts-security-bug_topic13879_post76622.html#76622</guid>
  </item> 
  <item>
   <title><![CDATA[&#146;Move posts&#146; security bug : I&amp;#039;ve searched for this and...]]></title>
   <link>https://forums.webwiz.net/move-posts-security-bug_topic13879_post76619.html#76619</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=4643">pedalcars</a><br /><strong>Subject:</strong> 13879<br /><strong>Posted:</strong> 18&nbsp;February&nbsp;2005 at 8:10am<br /><br />I've searched for this and can't find reference for any wwf version. I tested and verified it in WWF 7.9.<br /><br />Our forum has a number of private areas for different teams. Each team area has a moderator, obviously; also each area is set to be invisible to users without access rights (although topic titles still appear under active topics).<br /><br />One team moderator has noticed that he can "move" posts.<br /><br />He also noticed that when doing so, ALL forums are listed including all the hidden forums which normally he can't see.<br /><br />He can then successfully move a topic into another team's forum.<br /><br />At that point he cannot see the topic any longer, as it's in a forum he doesn't have permission to see or enter.<br /><br />This has two implications:<br /><br />Firstly, it is possible (as his proof of concept did) to insert messages into someone else's private forum.<br /><br />Secondly, it is possible that one could accidentally move an entire (confidential) topic into a rival team's forum, after which one cannot read it or remove it while the rival team can.]]>
   </description>
   <pubDate>Fri, 18 Feb 2005 08:10:54 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/move-posts-security-bug_topic13879_post76619.html#76619</guid>
  </item> 
 </channel>
</rss>