New Joymax Website exploit:
http://supportcp.joymax.com/demo/mail/exMailBoardAll.jsp
DO NOT SEND SUPPORT MESSAGE THAT HAVE ACCOUNT NAME AND PASSWORD TO JOYMAX!!!
All the post are public and if you look at rev6 forum, the exploit was found like this:
Pict1,
Pict2. Basically if you send them a message using your account that has a premium, you can from there browse from their website to the admin mailbox without any password with only 3 mouse clicks. Enter any username and password you want, they are all valid...
They better fix it soon, I don't even want to contact Joymax knowing that everyone can view everything...
This is another huge FAILED! for Joymax -_-
Credit goes to _TANGUITO_ for posting it on rev6 forum.
Joymax NEED to fix it as soon as possible before another exploit come out of it (sql injection, cross site scripting exploit etc...)