Oh no! Some styles failed to load. 😵 Please try reloading this page
Menu â–¾ â–´

#88 a bug that will allow anyone to mail

closed-fixed
5
2001-07-18
2001-07-11
Anonymous
No

Hi,

First let me thank you for a very well written
software. I would like to point out a problem that I'm
experiencing that I was able to even make it work with
your demo nocc version. The exploit is very easy:
Here's what I had to type:
http://nocc.sourceforge.net/demo/action.php?
action=aff_mail&mail=14&sort=1&sortdir=1&lang=en

and this will give small error but fully functional
web page with write/reply/ and stuff. Now, my real
concern is that with this bug, anyone who sends this
url or similar one the unauthenticated user can send
mail to anyone in the world without a single trace
back to whom he was. I am really put off with this
fact and I was hoping that the latest version 0.9.4
have addressed that problem but to my dismay it was
not so here I am reporting it. What I'd like to see
implemented is that in the case an Unauthenticated
user sends this kind of url he will be denied access.
Can you please do that ASAP. It's really important.

I will be keeping an eye on this thread. I will not
leave my email address for security reasons.

boshab

Discussion

  • Nicolas Chalanset

    • assigned_to: nobody --> nicocha
    • status: open --> open-fixed
     
  • Nicolas Chalanset

    Logged In: YES
    user_id=82865

    Fixed in CVS version.
    Could you confirm the bug is fixed by downloading the
    latest version available at
    http://nocc.sourceforge.net/download

    Thanks

     
  • Nicolas Chalanset

    • status: open-fixed --> closed-fixed
     

Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign Up No, Thank you