Ipswitch IMail User Mailbox Disclosure Vulnerability
BID:3432
Info
Ipswitch IMail User Mailbox Disclosure Vulnerability
| Bugtraq ID: | 3432 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1285 CVE-2001-1286 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Posted to Bugtraq by Niels Heinen <[email protected]> on Oct 12, 2001. |
| Vulnerable: |
Ipswitch IMail 7.0.4 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail User Mailbox Disclosure Vulnerability
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc.
A vulnerability exists in IMail which could enable an authenticated user to view the mailbox of another IMail user.
This accomplished using directory traversal techniques while logged into the server with a valid session ID.
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc.
A vulnerability exists in IMail which could enable an authenticated user to view the mailbox of another IMail user.
This accomplished using directory traversal techniques while logged into the server with a valid session ID.
Solution / Fix
Ipswitch IMail User Mailbox Disclosure Vulnerability
Solution:
Ipswitch has released a Hotfix which rectifies this issue. It should be noted that user's are required to have at least IMail 7.04 in order to successfully install this Hotfix.
Ipswitch IMail 7.0.4
Solution:
Ipswitch has released a Hotfix which rectifies this issue. It should be noted that user's are required to have at least IMail 7.04 in order to successfully install this Hotfix.
Ipswitch IMail 7.0.4
-
Ipswitch IMail Server 7.04 Hotfix 1
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail704.exe