TUCoPS :: Web :: General :: narrow~1.txt

Security flaw in narrowcastmedia.com

This requires that you already have a narrowcastmedia.com account.  Once you have an account
you can modify/view any of the other member's records.

I'm a member of narrowcastmedia.com and I recently stumbled across a
security flaw in there system.
When you login there is an option that allows you to modify your
account information. The address is 

http://www.narrowcastmedia.com/register/accountupdate.cfm?id=634&hostid=****&location=534

If you simply change the hostid part to any 4 digit you are able to
access other peoples acccounts. You have their name, phone #, address,
password and login, site address and more. 

Sincerely, MaTT

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH