BugTraq
Simple Machine Forum - Private section/posts/info disclosure Nov 08 2007 01:40PM
h3llcode hotmail it (1 replies)
Re: Simple Machine Forum - Private section/posts/info disclosure Nov 08 2007 10:36PM
Jindrich Kubec (kubecj asw cz)
At 14:40 8.11.2007, h3llcode (at) hotmail (dot) it [email concealed] wrote:
># In my forum i've a Staff area , and into that , there is a message that
>contain Bug,exploit or some others keywords...i'll put in the advanced
>search module # this keywords ,and i select "show results as
>messages"...and tadaaa...my priv8 zone can be read by everyone...

Logged in my forum as an admin.
Went into private section, found some unique keyword.
Had it searched in advanced search, it was found (as expected)

Logged off.
Had it searched in advanced search, not found (as expected)

What's your point then?

Jindrich Kubec <kubecj (at) avast (dot) com [email concealed]>

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus