The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15970
http://www.securityfocus.com/bid/10217