Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sun JavaMail API MimeMessage Infromation Disclosure Vulnerability

The following example is available:

User can do easily change msgno to whatever he wants. If he enters valid message no, then he will be able to view others message.
http://www.example.com/ReadMessage.jsp?msgno=10001
http://www.example.com/ReadMessage.jsp?msgno=10002







 

Privacy Statement
Copyright 2009, SecurityFocus