Secunia Logo
 
CVE Reference: CVE-2006-0139
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-0139

Description:
The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/24050

ST
  1015452

SAID
  Secunia Advisory: SA18342

MISC
  http://www.hamid.ir/security/megabbs.txt

CONFIRM
  http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924

BID
  16168


Return to the previous page.