Computalynx CMail Web File Access Vulnerability
BID:281
Info
Computalynx CMail Web File Access Vulnerability
| Bugtraq ID: | 281 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 1999 12:00AM |
| Updated: | May 25 1999 12:00AM |
| Credit: | This vulnerability was published in BUGTRAQ by Marc <[email protected]>. |
| Vulnerable: |
Computalynx CMail 2.3 |
| Not Vulnerable: | |
Discussion
Computalynx CMail Web File Access Vulnerability
A vulnerability in Computalynx's CMail allows remote malicious users to steal local files.
Compulynx's CMail is a Win32 mail server program. One of its features is allowing users to access their email with a web browser via a built-in web server.
The web server fails to check whether requested files fall outside its document tree (by using ".." in the URL). Thus attackers can retrieve files in the same drives as that on which the software resides if they know or can get it's filename.
A number of buffer overflows in the processing of SMTP and POP commands also exist.
A vulnerability in Computalynx's CMail allows remote malicious users to steal local files.
Compulynx's CMail is a Win32 mail server program. One of its features is allowing users to access their email with a web browser via a built-in web server.
The web server fails to check whether requested files fall outside its document tree (by using ".." in the URL). Thus attackers can retrieve files in the same drives as that on which the software resides if they know or can get it's filename.
A number of buffer overflows in the processing of SMTP and POP commands also exist.
Exploit / POC
Computalynx CMail Web File Access Vulnerability
http://www.example.com:8002/../spool/username/mail.txt
see http://www.securityfocus.com/bid/633.html for buffer overflow vulnerability
http://www.example.com:8002/../spool/username/mail.txt
see http://www.securityfocus.com/bid/633.html for buffer overflow vulnerability
Solution / Fix
Computalynx CMail Web File Access Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Computalynx CMail Web File Access Vulnerability
References:
References: