Rockliffe MailSite Express Information Disclosure Vulnerability
BID:15231
Info
Rockliffe MailSite Express Information Disclosure Vulnerability
| Bugtraq ID: | 15231 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2005 12:00AM |
| Updated: | Oct 28 2005 12:00AM |
| Credit: | Paul Craig of Security-Assessment.com is credited with the discovery of this vulnerability. |
| Vulnerable: |
Rockliffe MailSite Express 6.1.20 |
| Not Vulnerable: |
Rockliffe MailSite Express 6.1.22 |
Discussion
Rockliffe MailSite Express Information Disclosure Vulnerability
MailSite Express is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files in the security context of the Web server process. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
MailSite Express is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files in the security context of the Web server process. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
Exploit / POC
Rockliffe MailSite Express Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Rockliffe MailSite Express Information Disclosure Vulnerability
Solution:
The vendor has addressed this issue in MailSite Express version 6.1.22. Users are advised to contact the vendor for more information on obtaining updates.
Solution:
The vendor has addressed this issue in MailSite Express version 6.1.22. Users are advised to contact the vendor for more information on obtaining updates.
References
Rockliffe MailSite Express Information Disclosure Vulnerability
References:
References:
- MailSite Express Homepage (Rockliffe)
- Multiple vulnerabilities within RockLiffe MailSite Express WebMail ("Paul Craig"
)