Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Personal Sticky Threads v1.0.3c vbulletin Add-on problem Dec 23 2008 06:52PM
xl4nothing gmail com


Personal Sticky Threads is an addon for vbulletin that allows users to create personal stickies. There appears to be a small problem when toggling the personal sticky on a thread you do not have persmission to access.

If I am denied persmission to:

http://forums.somesite.com/showthread.php?t=7

Toggling personal stickies for the thread to on I am able to view the thread title, author, and pages:

http://forums.somesite.com/misc.php?do=togglestick&thread=47

This does not allow me access to the thread but does display information not intended to be viewed by me :)

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus