CVE-2008-3728
Summary
| CVE | CVE-2008-3728 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-20 16:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to determine the installation path, IP addresses, and error messages via direct requests to files under LOG/. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microworld Technologies | Mailscan | 5.6.a | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityReason - MicroWorld MailScan - Multiple Vulnerabilities within Admin-Webinterface | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| MailScan Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 'Re: MicroWorld MailScan - Multiple Vulnerabilities within Admin-Webinterface' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Exploit |
| www.oliverkarow.de/research/mailscan.txt | af854a3a-2127-422b-91ae-364da2661108 | www.oliverkarow.de | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| MicroWorld Technologies MailScan Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.