Booby Disclosure of Private Bookmarks

Monday, May 16 2005 @ 10:14 AM EDT

A vulnerability has been reported in Booby, which can be exploited by malicious people to disclose potentially sensitive information.

The vulnerability is caused due to an error in the public bookmark section. This can be exploited to disclose private bookmarks by enumerating bookmark IDs in "booby.php".

The vulnerability has been reported in version 1.0.0. Prior versions may also be affected.

SOFTWARE:
Booby 1.x

SOLUTION:
Update to version 1.0.1.
http://sourceforge.net/project/showfiles.php?group_id=87672

VERIFY ADVISORY:
http://secunia.com/advisories/15305/

Secunia Security Advisories

0 comments



http://community.securityteam.us/article.php/20050516101449573