Username and sim id enum

Disclosed: 2015-03-04 14:19:19 By 4lemon To mobilevikings
Unknown
Vulnerability Details
Look at this url (GET request) https://mobilevikings.be/en/sims/authorization/remove/admin/1036358/ - looks good - admin user detected https://mobilevikings.be/en/sims/authorization/remove/lloyd/1036358/ - looks good - lloyd user detected https://mobilevikings.be/en/sims/authorization/remove/lloydxxx/1036358/ - there is no lloydxxx user Sim card id (exist username should be used - lloyd in this case): https://mobilevikings.be/en/sims/authorization/remove/lloyd/1036358/ - sim card id 1036358 detected https://mobilevikings.be/en/sims/authorization/remove/lloyd/1036359/ - sim card id 1036359 detected https://mobilevikings.be/en/sims/authorization/remove/lloyd/1036351/ - there is no sim card id 1036351
Actions
View on HackerOne
Report Stats
  • Report ID: 47358
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report