Author Topic: Server Leaks Personal Information  (Read 16643 times)

0 Members and 1 Guest are viewing this topic.

June 03, 2010, 06:12:20 pm
Read 16643 times


  • Newbie

  • Offline
  • *

  • 1
This site if browse manually to their Calendar of Events page and provide a random ID/Password, than click on My Info leaks badly  the real members' info, including Home Addresses, CC (partial), Phones, etc Very buggy server...Likely, I did accidentally exploit the  Session or Cookie prediction flaw.. :o.
P.S. The link above might not work directly. You need to go and Click on "Enroll in Class".. 

June 03, 2010, 06:30:32 pm
Reply #1


  • Administrator
  • Hero Member

  • Online
  • *****

  • 3335
Ruining the bad guy's day