Qbik WinGate IMAP Service Directory Traversal Vulnerability
BID:18908
CVE-2006-2917 |Info
Qbik WinGate IMAP Service Directory Traversal Vulnerability
| Bugtraq ID: | 18908 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2006 12:00AM |
| Updated: | Jul 11 2006 09:48PM |
| Credit: | Discovered by Tan Chew Keong, Secunia Research. |
| Vulnerable: |
Qbik WinGate 6.1.3 .1096 Qbik WinGate 6.1.2 .1094 |
| Not Vulnerable: |
Qbik WinGate 6.1.4 .1099 |
Discussion
Qbik WinGate IMAP Service Directory Traversal Vulnerability
The IMAP service of WinGate is prone to a directory-traversal vulnerability.
Reportedly, an authenticated user can access sensitive information such as other users' email and can create or remove arbitrary directories from a vulnerable computer.
Versions 6.1.2.1094 and 6.1.3.1096 are reported to be affected. Other versions may be affected as well.
The IMAP service of WinGate is prone to a directory-traversal vulnerability.
Reportedly, an authenticated user can access sensitive information such as other users' email and can create or remove arbitrary directories from a vulnerable computer.
Versions 6.1.2.1094 and 6.1.3.1096 are reported to be affected. Other versions may be affected as well.
Exploit / POC
Qbik WinGate IMAP Service Directory Traversal Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Qbik WinGate IMAP Service Directory Traversal Vulnerability
Solution:
The vendor has released version 6.1.4 Build 1099 to address this issue.
Qbik WinGate 6.1.2 .1094
Qbik WinGate 6.1.3 .1096
Solution:
The vendor has released version 6.1.4 Build 1099 to address this issue.
Qbik WinGate 6.1.2 .1094
-
Qbik WinGate 6.1.4.1099
http://www.wingate.com/download.php
Qbik WinGate 6.1.3 .1096
-
Qbik WinGate 6.1.4.1099
http://www.wingate.com/download.php
References
Qbik WinGate IMAP Service Directory Traversal Vulnerability
References:
References: