Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Melange Chat Session Header Information Disclosure Vulnerability


Melange Chat is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly secure HTTP request data.

An attacker can exploit this issue to retrieve the credentials of an arbitrary user.

If an administrative user's credentials are retrieved, successful exploitation may result in the compromise of the affected application; other attacks are also possible.







 

Privacy Statement
Copyright 2009, SecurityFocus