WHID 2004-9: Billing and personal information leakage due to lack of authentication on a phone company web site
A billing information system required only phone number and zip code to pull up account details
Additional information:
- A security tale: From vulnerability discovery to disaster [Search Security, Jun 14 2004]
Attack Method:
Incident Outcome: