Date:
11 January 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Process Validation
A priority code, used to get free platinum pass to MacWorld Expo, was validated on the client and enabled anyone get the pass for free. While "grutz" informed the organizers about it, when going over their log files they found out that others abused the vulnerability without letting anyone know about it.
References: