Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IceWarp Web Mail Session ID Disclosure Vulnerability

No exploit is required. The following example demonstrates how a malicious user may access another user's account provided they have acquired a valid session ID:

http://www.example.com/view.html?id=[acquired ID]







 

Privacy Statement
Copyright 2008, SecurityFocus