phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact".
Link | Tags |
---|---|
http://www.securityfocus.com/bid/17959 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26499 | vdb entry |
http://secunia.com/advisories/20088 | third party advisory vendor advisory |
http://forums.phpcoin.com/index.php?showtopic=5941 | |
http://www.vupen.com/english/advisories/2006/1788 | vdb entry |