lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060315211006.17523.qmail@securityfocus.com> Date: 15 Mar 2006 21:10:06 -0000 From: shurik.f@...il.com To: bugtraq@...urityfocus.com Subject: Vulnerability in e-gold Vulnerability was fixed in https://www.e-gold.com/acct/confirm.asp money transfer script. Problem description: If authenticated user is referred to the script AccounID/PassPhrase validation is not performed. By redirecting user to URL https://www.e-gold.com/acct/confirm.asp?AccountID=123456&PassPhrase=somestring&PayeeAccount=MY_ACCOUNT&Amount=100&PAY_IN=1&WORTH_OF=Gold&Memo=Donation&IGNORE_RATE_CHANGE=y it's possible to transfer money to another account without validation. On march, 13th 2006 reported to e-gold On march, 14th 2006 fixed Details posted on http://bhunter.awardspace.com/vuln-en.html I did get a small "buggs bounty" from e-gold for this info.