VisNetic Mail Server Multiple File Include Vulnerabilities
BID:19002
Info
VisNetic Mail Server Multiple File Include Vulnerabilities
| Bugtraq ID: | 19002 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0818 CVE-2006-0817 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 17 2006 12:00AM |
| Updated: | Jul 17 2006 12:00AM |
| Credit: | Tan Chew Keong of Secunia Research is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Visnetic Mail Server 8.3.5 |
| Not Vulnerable: |
Visnetic Mail Server 8.5 5 |
Discussion
VisNetic Mail Server Multiple File Include Vulnerabilities
VisNetic Mail Server is prone to multiple local file-include vulnerabilities and a remote file includes vulnerability. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files or local files containing malicious PHP code and execute it in the context of the web server process. This may allow the attacker to compromise the application and access the underlying system.
Version 8.3.5 is vulnerable to this issue; prior versions may also be affected.
VisNetic Mail Server is prone to multiple local file-include vulnerabilities and a remote file includes vulnerability. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files or local files containing malicious PHP code and execute it in the context of the web server process. This may allow the attacker to compromise the application and access the underlying system.
Version 8.3.5 is vulnerable to this issue; prior versions may also be affected.
Exploit / POC
VisNetic Mail Server Multiple File Include Vulnerabilities
Attackers can exploit this issue with a web-client.
The following proof of concept URIs are available:
Attackers can exploit this issue with a web-client.
The following proof of concept URIs are available:
Solution / Fix
VisNetic Mail Server Multiple File Include Vulnerabilities
Solution:
The vendor has released version 8.5.0.5 to address this issue. Contact the vendor for further information.
Visnetic Mail Server 8.3.5
Solution:
The vendor has released version 8.5.0.5 to address this issue. Contact the vendor for further information.
Visnetic Mail Server 8.3.5
-
Visnetic VisNetic MailServer All Windows Platform
http://www.deerfield.com/download/visnetic-mailserver/thanks.htm?dlid= 10&profileid=19&productid=90&url=ftp://ftp.deerfield.com/pub/current/v mssetup_en.exe&bp=0
References
VisNetic Mail Server Multiple File Include Vulnerabilities
References:
References:
- VisNetic Mail Server (VisNetic)
- VisNetic Mail Server Two File Inclusion Vulnerabilities (Secunia Research)