admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users.Referenceshttp://www.securityfocus.com/archive/1/453966/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/30805http://www.securityfocus.com/bid/21514http://secunia.com/advisories/23318http://securityreason.com/securityalert/2019