Simple Chat 1.x - User Information Disclosure

EDB-ID:

22409

CVE:



Author:

subj

Type:

remote


Platform:

Multiple

Date:

2003-03-21


source: https://www.securityfocus.com/bid/7168/info

Simple Chat! does not restrict access to sensitive information by default. An attacker could use this information to launch attacks against other users.

http://www.example.com/chat/data/usr