Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ATutor Chat Logs Remote Information Disclosure Vulnerability

ATutor is prone to a remote information disclosure vulnerability. This issue is due to a failure in the application to perform proper access validation before granting access to privileged information.

A remote attacker can exploit this vulnerability and make repeated GET requests for the chat logs, effectively retrieving all chat archives. Information obtained may aid an attacker in further attacks.







 

Privacy Statement
Copyright 2009, SecurityFocus