Ipswitch IMail Account Information Brute Force Vulnerability
BID:3424
Info
Ipswitch IMail Account Information Brute Force Vulnerability
| Bugtraq ID: | 3424 |
| Class: | Design Error |
| CVE: |
CVE-2001-1280 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by Arne Vidstrom <[email protected]> on Oct 11, 2001. |
| Vulnerable: |
Ipswitch IMail 7.0.4 Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.2 |
| Not Vulnerable: | |
Exploit / POC
Ipswitch IMail Account Information Brute Force Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Ipswitch IMail Account Information Brute Force Vulnerability
Solution:
Ipswitch has released a Hotfix which rectifies this issue. It should be noted that users require IMail 7.04 in order to apply the Hotfix:
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/IM704HF1.exe
Ipswitch IMail 7.0.4
Solution:
Ipswitch has released a Hotfix which rectifies this issue. It should be noted that users require IMail 7.04 in order to apply the Hotfix:
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/IM704HF1.exe
Ipswitch IMail 7.0.4
-
Ipswitch IM704HF1.EXE
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/IM704HF1.exe
References
Ipswitch IMail Account Information Brute Force Vulnerability
References:
References:
- IMail Server Homepage (Ipswitch)
- IMail Server Support Center (IPSwitch)