Ipswitch IMail Server User Modification Vulnerability
BID:3429
Info
Ipswitch IMail Server User Modification Vulnerability
| Bugtraq ID: | 3429 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1281 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by Arne Vidstrom <[email protected]> on Oct 11, 2001. |
| Vulnerable: |
Ipswitch IMail 7.0.4 Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.2 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail Server User Modification Vulnerability
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc.
It is possible for an unauthorized user to modify user information in the Web Messaging Service of Ipswitch. It is possible to specify another userid to whom changes in the editing form will be applied by simply modifying a hidden variable.
Successful exploitation of this vulnerability could lead to a denial of service for the victim user.
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc.
It is possible for an unauthorized user to modify user information in the Web Messaging Service of Ipswitch. It is possible to specify another userid to whom changes in the editing form will be applied by simply modifying a hidden variable.
Successful exploitation of this vulnerability could lead to a denial of service for the victim user.
Exploit / POC
Ipswitch IMail Server User Modification Vulnerability
There is no exploit required.
There is no exploit required.
References
Ipswitch IMail Server User Modification Vulnerability
References:
References:
- IMail Server Homepage (Ipswitch)
- IMail Server Support Center (IPSwitch)