TUCoPS :: Web :: Specific Sites :: b06-1040.htm

Vulnerability fixed in E-gold
Vulnerability fixed in E-gold
Vulnerability fixed in E-gold



Hello full-disclosure, bugtraq

  Netsling (shurik.f_(at)_gmail.com) reported vulnerability in E-gold.

  Vulnerability was reported and fixed in E-gold partner payment script.
  It  was  possible  to  transfer  money  from  E-gold  account  without
  knowledge of AccounID/PassPhrase if user is logged on.

  Vulnerability details can be found at
http://bhunter.awardspace.com/vuln-en.html 

  The most interesting thing here is E-gold reaction:

  1. Vendor fixed vulnerability within 24 hours.
  2. Vendor decided to reward researcher without any request from his
  side.
  3. Vendor gave permission to publish vulnerability information.

  Just ideal. I hope Microsoft to read this.

  Vulnerability  was  found  and  reported  to  E-gold  by nestling, Web
  software  developer  from  Russia. Please contact him directly, if you
  have  any questions, because I was only asked to translate and publish
  this information.
  

-- 
/3APA3A
http://www.security.nnov.ru/ 


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH