Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26508 | vdb entry |
http://www.securityfocus.com/archive/1/483437/100/0/threaded | mailing list |