SPA-PRO Mail @Solomon IMAP Server Multiple Directory Traversal Vulnerabilities
BID:13838
Info
SPA-PRO Mail @Solomon IMAP Server Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 13838 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2005 12:00AM |
| Updated: | Jun 02 2005 12:00AM |
| Credit: | Tan Chew Keong <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
E-POST Inc. SPA-PRO Mail @Solomon 4.0 4 E-POST Inc. SPA-PRO Mail @Solomon 4.0 3 E-POST Inc. SPA-PRO Mail @Solomon 4.0 1 |
| Not Vulnerable: |
E-POST Inc. SPA-PRO Mail @Solomon 4.0 5 |
Discussion
SPA-PRO Mail @Solomon IMAP Server Multiple Directory Traversal Vulnerabilities
SPA-PRO Mail @Solomon IMAP Server is susceptible to directory traversal vulnerabilities in multiple IMAP commands. These issues are due to a failure of the application to properly sanitize user-supplied input.
These issues allow remote attackers to read, modify, or destroy other user's mail, as well as create arbitrary directories, rename directories, or delete empty directories. The information gained from accessing other user's email may aid malicious users in further attacks.
SPA-PRO Mail @Solomon IMAP Server is susceptible to directory traversal vulnerabilities in multiple IMAP commands. These issues are due to a failure of the application to properly sanitize user-supplied input.
These issues allow remote attackers to read, modify, or destroy other user's mail, as well as create arbitrary directories, rename directories, or delete empty directories. The information gained from accessing other user's email may aid malicious users in further attacks.
Exploit / POC
SPA-PRO Mail @Solomon IMAP Server Multiple Directory Traversal Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
SPA-PRO Mail @Solomon IMAP Server Multiple Directory Traversal Vulnerabilities
Solution:
It is reported that the vendor has released version 4.05 of the affected package to address this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
Solution:
It is reported that the vendor has released version 4.05 of the affected package to address this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
References
SPA-PRO Mail @Solomon IMAP Server Multiple Directory Traversal Vulnerabilities
References:
References:
- SPA-PRO Mail @Solomon (E-POST Inc.)
- SPA-PRO Mail @Solomon IMAP Server Directory Traversal and Buffer Overflow Vulner (SIG^2 Vulnerability Research)