AlphaMail Log File Information Disclosure Vulnerability
BID:19996
CVE-2006-4787 |Info
AlphaMail Log File Information Disclosure Vulnerability
| Bugtraq ID: | 19996 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 13 2006 12:00AM |
| Updated: | Sep 14 2006 03:52PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
AlphaMail AlphaMail 1.0.15 |
| Not Vulnerable: |
AlphaMail AlphaMail 1.0.16 |
Discussion
AlphaMail Log File Information Disclosure Vulnerability
AlphaMail is prone to a local information-disclosure vulnerability because the application fails to properly secure sensitive information.
This issue allows local attackers to gain access to administrative account-authentication credentials.
Versions prior to 1.0.16 are vulnerable.
AlphaMail is prone to a local information-disclosure vulnerability because the application fails to properly secure sensitive information.
This issue allows local attackers to gain access to administrative account-authentication credentials.
Versions prior to 1.0.16 are vulnerable.
Exploit / POC
AlphaMail Log File Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
AlphaMail Log File Information Disclosure Vulnerability
Solution:
The vendor has released version 1.0.16 to address this issue. Please see the references for details.
AlphaMail AlphaMail 1.0.15
Solution:
The vendor has released version 1.0.16 to address this issue. Please see the references for details.
AlphaMail AlphaMail 1.0.15
-
AlphaMail alphamail-1.0.16.tar.gz
http://alphamail.uoosl.org/releases/alphamail-1.0.16.tar.gz