Print Page | Close Window

Possible Security Bug

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=4078
Printed Date: 02 April 2026 at 4:42am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: Possible Security Bug
Posted By: kbannon
Subject: Possible Security Bug
Date Posted: 05 July 2003 at 4:40am

Just a quickie - I was asked to place a forum up on a site which is reserved just for about a dozen people. Therefore the forum is configured not to allow new registrations nor can guests view threads (I know that it may be better off within a members area). The screen appears relatively blank which is fine.

However, if anyone does a search say for an 'e' then they can view pretty much every topic. Clicking on the topics though does not let them view the thread.

Just thought I'd let you know.



-------------
I don't suffer from insanity, I enjoy every minute of it.



Replies:
Posted By: donhill
Date Posted: 05 July 2003 at 6:43am

Yes you are correct and thx for pointing this out.

If you place the code here in the search_form.asp it will direct all guests to the login page each time. Place it after all the includes and the <%

' Redirect guests to the login page
If blnGuest Then Response.Redirect "login_user.asp"



Posted By: donhill
Date Posted: 05 July 2003 at 5:59pm

Further to this one.

Above fix stops guests accessing forums via search bug but once registered and in the forums the search button if ALL FORUMS is selected allows results from ALL Forums not just the forums allwoed for that user.




Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net