5
CVSSv2

CVE-2004-1968

Published: 26/04/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and previous versions allows remote malicious users to read arbitrary messages by modifying the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

openbb openbb 1.0_.0_rc1

openbb openbb 1.0_.0_rc2

openbb openbb 1.0_.0_beta1

openbb openbb 1.0_.0_rc3

openbb openbb 1.0_.5

openbb openbb 1.0_.6

Exploits

source: wwwsecurityfocuscom/bid/10217/info It has been reported that OpenBB is affected by a private message disclosure vulnerability This issue is due to a design error that fails to validate user credentials This issue might allow an attacker to read arbitrary private messages posted to the bulletin board; limiting confidentiality ...