CVE-2007-3592 Information

Description

PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.

Reference

http://osvdb.org/37820 http://secunia.com/advisories/25926 http://sourceforge.net/project/shownotes.php?release_id=520558&group_id=175118 http://www.securityfocus.com/bid/24763 https://exchange.xforce.ibmcloud.com/vulnerabilities/35262

Share on: