Basilix Webmail File Disclosure Vulnerability
BID:2995
Info
Basilix Webmail File Disclosure Vulnerability
| Bugtraq ID: | 2995 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1045 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was submitted to BugTraq on July 6th, 2001 by "karol _" <[email protected]>. |
| Vulnerable: |
Basilix Webmail 1.0 3beta Basilix Webmail 1.0 2beta |
| Not Vulnerable: | |
Discussion
Basilix Webmail File Disclosure Vulnerability
Basilix is a web-based mail application. It offers features such as mail attachments, address book, multiple language and theme support.
During operation, Basilix opens a PHP include file using a variable as the filename that can be supplied remotely. Basilix do not properly filter malicious user-supplied input. It is possible for remote attackers to have Basilix attempt to 'include' an arbitrary webserver-readable file.
This vulnerability may disclose sensitive information contained in arbitrary web-readable files. It may also be possible for remote attackers to execute php files.
Basilix is a web-based mail application. It offers features such as mail attachments, address book, multiple language and theme support.
During operation, Basilix opens a PHP include file using a variable as the filename that can be supplied remotely. Basilix do not properly filter malicious user-supplied input. It is possible for remote attackers to have Basilix attempt to 'include' an arbitrary webserver-readable file.
This vulnerability may disclose sensitive information contained in arbitrary web-readable files. It may also be possible for remote attackers to execute php files.
Solution / Fix
Basilix Webmail File Disclosure Vulnerability
Solution:
The vendor knows of this issue and has posted details on how to fix it at:
http://basilix.org/index.php3?page=home&lang=en
Solution:
The vendor knows of this issue and has posted details on how to fix it at:
http://basilix.org/index.php3?page=home&lang=en