PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Elite_bulletin_board |
Elite_bulletin_board |
* |
* |
References