Nevrona MiraMail Sensitive File Plain Text Storage Vulnerability
BID:3843
Info
Nevrona MiraMail Sensitive File Plain Text Storage Vulnerability
| Bugtraq ID: | 3843 |
| Class: | Design Error |
| CVE: |
CVE-2002-0110 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 10 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered and posted to Bugtraq by Chris Lathem <[email protected]>. |
| Vulnerable: |
Nevrona Designs MiraMail 1.0 4 |
| Not Vulnerable: | |
Discussion
Nevrona MiraMail Sensitive File Plain Text Storage Vulnerability
MiraMail stores user's POP account authentication information, user account and group information in one .ini file. Due to a design flaw this file is stored in plain text.
Any user with access to the directory in which MiraMail is installed will have access to this file.
MiraMail stores user's POP account authentication information, user account and group information in one .ini file. Due to a design flaw this file is stored in plain text.
Any user with access to the directory in which MiraMail is installed will have access to this file.
Exploit / POC
Nevrona MiraMail Sensitive File Plain Text Storage Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Nevrona MiraMail Sensitive File Plain Text Storage Vulnerability
Solution:
The vendor has acknowledged this issue and will address it in MiraMail 1.05. The release date of version 1.05 is not yet known.
Solution:
The vendor has acknowledged this issue and will address it in MiraMail 1.05. The release date of version 1.05 is not yet known.
References
Nevrona MiraMail Sensitive File Plain Text Storage Vulnerability
References:
References:
- MiraMail Homepage (Nevrona Designs)