Date:
25 July 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization
In a classic case of lack of proper separation between the production and development sites, an application under production with lack of proper authentication and authorization was installed on a hospital's public web site, enabling anyone to query a database of 51,000 names, addresses and social security numbers.
References: