WHID 2006-2: GSA takes down eOffer after finding security flaw

Attack Information
WHID ID: 
2006-2
Date Occured: 
26 Feb 2006
Attack Method: 
Outcome Information
Outcome: 

Documents uploaded to GSA site where accessed using a predictable sequential identifier without requiring special permissions. The documents where available both for viewing and modifying. The site was in service for more than 18 months until the vulnerability was discovered.

Additional information: