Vulnerabilities > CVE-2006-2422 - Unspecified vulnerability in Coinsoft Technologies PHPcoin
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact".
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
References
- http://forums.phpcoin.com/index.php?showtopic=5941
- http://forums.phpcoin.com/index.php?showtopic=5941
- http://secunia.com/advisories/20088
- http://secunia.com/advisories/20088
- http://www.securityfocus.com/bid/17959
- http://www.securityfocus.com/bid/17959
- http://www.vupen.com/english/advisories/2006/1788
- http://www.vupen.com/english/advisories/2006/1788
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26499
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26499