The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://osvdb.org/51205 | vdb entry |
http://www.securityfocus.com/bid/33017 | vdb entry |
http://secunia.com/advisories/33342 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/499562/100/0/threaded | mailing list |