Описание
The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.
Ссылки
- ExploitPatchVendor Advisory
- ExploitPatchVendor Advisory
- PatchVendor Advisory
- Patch
- ExploitPatchVendor Advisory
- ExploitPatchVendor Advisory
- PatchVendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:pd9_software:megabbs:2.0:*:*:*:*:*:*:*
cpe:2.3:a:pd9_software:megabbs:2.1:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00985
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.
EPSS
Процентиль: 76%
0.00985
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other