Cobalt Qube Webmail Directory Traversal Vulnerability
BID:2987
Info
Cobalt Qube Webmail Directory Traversal Vulnerability
| Bugtraq ID: | 2987 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2001 12:00AM |
| Updated: | Jul 05 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq by KF <[email protected]> on July 5th, 2001. |
| Vulnerable: |
Cobalt Qube Webmail 1.0 |
| Not Vulnerable: | |
Discussion
Cobalt Qube Webmail Directory Traversal Vulnerability
Cobalt Qube is an fully-featured network "server appliance".
It includes pre-installed tools and applications and can be put online with very little configuration.
A vulnerability in Cobalt Qube's webmail implementation allows remote attackers to traverse directories. Malformed HTTP requests can be crafted to display sensitive information about the host.
Cobalt Qube is an fully-featured network "server appliance".
It includes pre-installed tools and applications and can be put online with very little configuration.
A vulnerability in Cobalt Qube's webmail implementation allows remote attackers to traverse directories. Malformed HTTP requests can be crafted to display sensitive information about the host.
Solution / Fix
Cobalt Qube Webmail Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Cobalt Qube Webmail 1.0
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Cobalt Qube Webmail 1.0
-
Sun Cobalt Qube3-ml-Security-2.0.1-10626.pkg
ftp://ftp.cobalt.com