include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.
Link | Tags |
---|---|
http://secunia.com/advisories/24402 | third party advisory vendor advisory |
http://code.google.com/p/simpleinvoices/issues/detail?id=35 | |
https://sourceforge.net/project/shownotes.php?group_id=164303&release_id=491300 | |
http://www.securityfocus.com/bid/22818 | vdb entry patch vendor advisory |
http://osvdb.org/33860 | vdb entry |
http://forum.tufat.com/showthread.php?p=116753#post116753 |