Trlinux Postaci Webmail Password Disclosure Vulnerability
BID:2029
Info
Trlinux Postaci Webmail Password Disclosure Vulnerability
| Bugtraq ID: | 2029 |
| Class: | Access Validation Error |
| CVE: |
CVE-2000-1100 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 30 2000 12:00AM |
| Updated: | Jul 11 2009 03:56AM |
| Credit: | Discovered and posted to Bugtraq on Nov 30, 2000 by Michael R. Rudel <[email protected]>. |
| Vulnerable: |
Trlinux Postaci Webmail 1.1.3 |
| Not Vulnerable: | |
Exploit / POC
Trlinux Postaci Webmail Password Disclosure Vulnerability
Exploit provided by Michael R. Rudel <[email protected]>:
http://target/includes/global.inc
Exploit provided by Michael R. Rudel <[email protected]>:
http://target/includes/global.inc
Solution / Fix
Trlinux Postaci Webmail Password Disclosure Vulnerability
Solution:
This was sent from Lars Christian Nygård <[email protected]> :
This should not be possible if you follow the installation instructions properly and add the .inc extension to the AddHandle/Addtype in apache. This IS described and pointed out in the ../doc/INSTALL document of Postaci as crucial for security.
Solution:
This was sent from Lars Christian Nygård <[email protected]> :
This should not be possible if you follow the installation instructions properly and add the .inc extension to the AddHandle/Addtype in apache. This IS described and pointed out in the ../doc/INSTALL document of Postaci as crucial for security.