Kebi WebMail Unauthenticated Administration Vulnerability
BID:3655
Info
Kebi WebMail Unauthenticated Administration Vulnerability
| Bugtraq ID: | 3655 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2001-0953 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Disclosed to BugTraq on Dec 8, 2001 by Secret <[email protected]> |
| Vulnerable: |
Nara Vision Kebi Community 1.0 enterprise version Nara Vision Kebi Community 1.0 academy version |
| Not Vulnerable: | |
Discussion
Kebi WebMail Unauthenticated Administration Vulnerability
Kebi Webmail is a korean web mail solution provided as a component of various Kebi Community solutions. This software is reported to leave administrator functions available in a world accessible directory. The functions can reportedly be accessed in a directory /a/ off the main web-mail directory, potentially disclosing information and allowing unauthorized modification of web mail functions.
Kebi Webmail is a korean web mail solution provided as a component of various Kebi Community solutions. This software is reported to leave administrator functions available in a world accessible directory. The functions can reportedly be accessed in a directory /a/ off the main web-mail directory, potentially disclosing information and allowing unauthorized modification of web mail functions.
Exploit / POC
Kebi WebMail Unauthenticated Administration Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Kebi WebMail Unauthenticated Administration Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Kebi WebMail Unauthenticated Administration Vulnerability
References:
References:
- Company Web Site (Nara Vision)