Sun JavaMail API MimeMessage Infromation Disclosure Vulnerability

The following example is available:

User can do easily change msgno to whatever he wants. If he enters valid message no, then he will be able to view others message.
http://www.example.com/ReadMessage.jsp?msgno=10001
http://www.example.com/ReadMessage.jsp?msgno=10002


 

Privacy Statement
Copyright 2010, SecurityFocus