Ipswitch IMail Domain Administration Privilege Escalation Vulnerability
BID:3766
Info
Ipswitch IMail Domain Administration Privilege Escalation Vulnerability
| Bugtraq ID: | 3766 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1211 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2001 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered by Zeeshan Mustafa <[email protected]> and posted to the BugTraq mailing list on December 31, 2001. |
| Vulnerable: |
Ipswitch IMail 7.0.4 Ipswitch IMail 7.0.3 Ipswitch IMail 7.0.2 Ipswitch IMail 7.0.1 Ipswitch IMail 6.4 Ipswitch IMail 6.3 Ipswitch IMail 6.2 Ipswitch IMail 6.1 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail Domain Administration Privilege Escalation Vulnerability
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc. IMail also includes support for multiple domains, and web based administration. It runs on Microsoft Windows platforms.
There is a vulnerability with the authentication process for this web administration tool. Any valid administrator account may make changes to any domain on the server. A malicious administrator is able to abuse this access to modify or delete information associated with any hosted domain.
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc. IMail also includes support for multiple domains, and web based administration. It runs on Microsoft Windows platforms.
There is a vulnerability with the authentication process for this web administration tool. Any valid administrator account may make changes to any domain on the server. A malicious administrator is able to abuse this access to modify or delete information associated with any hosted domain.
Exploit / POC
Ipswitch IMail Domain Administration Privilege Escalation Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
Ipswitch IMail Domain Administration Privilege Escalation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ipswitch IMail Domain Administration Privilege Escalation Vulnerability
References:
References:
- IMail Home Page (Ipswitch)