Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: August 20, 2009
Lauren Gerber
-1
Vote
0

Posting About The Stiva Forum Problem

 

One of the best ways to communicate with the online public is through forums. If you have a question about any topic all you need to do is go to a related forum and ask a question, chances are that either somebody from that online community, or alternatively the people incharge of the site itself, will answer the question for you. Forums are a great way of starting discussions for a product that you are marketing, as it gets people interested as well as interactive. Unfortunately I am here to share news about vulnerabilities that have hit one of these wonderful interactive online forums. The Stiva Forum has been affected by multiple vulnerabilities which could cause a lot of damage.XSS_attacks.jpg

For those of you who may not have sufficient knowledge with regard to the Stiva Forum, not to worry, I will enlighten you on this matter. Stiva Forum is designed to help users put a forum on their websites easily and effectively. It gives your website visitors the ability to reply as well as post brand new topics. With the use of an administration page and a strong password, you will be able to manage the forum easily. There are many more wonderful remarkable features with regard to this forum. In order to make use of this fantastic forum, your hosting account needs to support both MYSQL as well as PHP. You can make use of any browser, you may be using the Internet Explorer 6 browser which is perfectly fine. Some of the files of Internet Explorer 6 include: activate.dll, ACPI.BAT, clean.vbs as well as chat.inf. The main factor is that you have internet access, as it is an online program and requires internet access. 

Now it is time for me to provide you with some more information with regard to these multiple vulnerabilities. These vulnerabilities may be actively exploited by malicious online attackers in order to do cross site scripting attacks. Malicious attackers could inject malicious code into the web pages that are usually viewed by the victim. The most alarming aspect with regard to these types of attacks is that, to the end user everything appears authentic and nothing seems to be wrong. The reality of the situation is quite different, as everything is actually wrong. A malicious online attacker may in fact be committing data theft, gaining unauthorized access to your machine as well as taking a look at all your highly sensitive information, with the inclusion of your passwords.XSS.jpg

I am sure you are wondering why the potential for this type of attack has affected the Stiva Forum. Basically certain input which is passed from the URL to the "id"parameter in the forum.PHP, is not properly modified prior to being returned to the user. This causes the problems that can be exploited by malicious online criminals in order to execute arbitrary HTML and script code. This will be done in the specific browser session of a user, in the context of a site that has been tampered with.

Although these vulnerabilities may be seen as less critical, this does not mean that we should ignore them. It is still extremely important to know which versions have been affected in order to stay safe. The version of Stiva that was affected is version 1.0. It is important for all users to know that the possibility of other Stiva Forum versions also being affected is possible. Unfortunately, at the moment this vulnerability remains unpatched, so it is in your best interest to be aware and to stay safe. Don't let this Stiva Forum issue to stop you from having a marvelous interactive forum on your website.

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 10, 2010
misa campo is much better u *** tards more..
March 10, 2010
go to bleeping computer.com..d .. r.com..downloada file called Rkill. But first if you are having trouble... more..
March 10, 2010
dr. guard is the worst i've encountered. I manually made all the deletions of files and registry entries.... more..
more comments..
rss
Home > Computer Security > Posting About The Stiva Forum Problem