exploit-db-mirror/exploits/php/webapps/28322.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

7 lines
No EOL
469 B
Text

source: http://www.securityfocus.com/bid/19278/info
TinyPHPForum is prone to an information-disclosure vulnerability. This issue arises when a script allows a remote untrusted source to change a victim user's email address, and have their login credentials returned to an attacker.
Information that the attacker gathers by exploiting this vulnerability may aid in other attacks.
http://www.example.com/error.php?err=200&uname=victim&email=attacker@example.com