PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
BID:16168
Info
PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
| Bugtraq ID: | 16168 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2006 12:00AM |
| Updated: | Jan 09 2006 12:00AM |
| Credit: | Hamid Ebadi is credited with the discovery of this vulnerability. |
| Vulnerable: |
PD9 Software MegaBBS 2.1 PD9 Software MegaBBS 2.0 |
| Not Vulnerable: | |
Discussion
PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
MegaBBS is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly verify user-supplied data.
An attacker can exploit this issue to view private messages of other users. Information obtained may aid in further attacks.
MegaBBS is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly verify user-supplied data.
An attacker can exploit this issue to view private messages of other users. Information obtained may aid in further attacks.
Exploit / POC
PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
Solution:
The vendor has released a patch addressing this issue:
PD9 Software MegaBBS 2.0
PD9 Software MegaBBS 2.1
Solution:
The vendor has released a patch addressing this issue:
PD9 Software MegaBBS 2.0
-
PD9 Software send-private-message.zip
http://www.pd9soft.com/megabbs/forums/get-attachment.asp?attachmentid= 1758
PD9 Software MegaBBS 2.1
-
PD9 Software send-private-message.zip
http://www.pd9soft.com/megabbs/forums/get-attachment.asp?attachmentid= 1758
References
PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
References:
References:
- Homepage (PD9 Software)
- RE: MegaBBS 2.1 updates (PD9 Software)