chacmool Private Message System 1.1.3 - 'send.php' Arbitrary Message Access
Author: digital ex
type: webapps
platform: php
port:
date_added: 2004-11-12
date_updated: 2013-03-12
verified: 1
codes: OSVDB-11791
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/11671/info
Private Message System is reported prone to multiple vulnerabilities that can allow remote attackers to carry out cross-site scripting attacks and disclose arbitrary private messages.
Private Message System 1.1.3 is reported vulnerable to these issue, however, it is possible that other version are affected as well.
http://www.example.com/message_send.php?quote=[ID]