NOCC Webmail Unauthenticated Outgoing Mail Access
BID:3677
Info
NOCC Webmail Unauthenticated Outgoing Mail Access
| Bugtraq ID: | 3677 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2001 12:00AM |
| Updated: | Jul 11 2001 12:00AM |
| Credit: | Posted by boshab to the NOCC bug tracking system on July 11, 2001. |
| Vulnerable: |
NOCC NOCC 0.9.4 NOCC NOCC 0.9.3 NOCC NOCC 0.9.2 NOCC NOCC 0.9.1 NOCC NOCC 0.9 |
| Not Vulnerable: |
NOCC NOCC 0.9.5 |
Discussion
NOCC Webmail Unauthenticated Outgoing Mail Access
NOCC is a web based email client implemented in PHP4. It includes support for POP3, SMTP and IMAP servers, MIME attachments and multiple languages.
A malicious user may construct a URL access a NOCC script such that, while an error is generated, they are able to continue. From this point, the unauthorized user may successfully send outgoing email. The email will not reflect the identity of the unauthorized user.
NOCC is a web based email client implemented in PHP4. It includes support for POP3, SMTP and IMAP servers, MIME attachments and multiple languages.
A malicious user may construct a URL access a NOCC script such that, while an error is generated, they are able to continue. From this point, the unauthorized user may successfully send outgoing email. The email will not reflect the identity of the unauthorized user.
Exploit / POC
NOCC Webmail Unauthenticated Outgoing Mail Access
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
NOCC Webmail Unauthenticated Outgoing Mail Access
Solution:
This vulnerability has been fixed in version 0.9.5 of NOCC.
Solution:
This vulnerability has been fixed in version 0.9.5 of NOCC.
References
NOCC Webmail Unauthenticated Outgoing Mail Access
References:
References:
- [ #440319 ] a bug that will allow anyone to mail (boshab)
- NOCC Homepage (NOCC)