Endymion Sake Mail Null Character File Disclosure Vulnerability
BID:4223
Info
Endymion Sake Mail Null Character File Disclosure Vulnerability
| Bugtraq ID: | 4223 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0418 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovery of this issue is credited to Rudi Carrell. |
| Vulnerable: |
Endymion Sake Mail 1.0.36 Endymion Sake Mail 1.0.35 Endymion Sake Mail 1.0.34 Endymion Sake Mail 1.0.33 Endymion Sake Mail 1.0.31 Endymion Sake Mail 1.0.30 Endymion Sake Mail 1.0.29 Endymion Sake Mail 1.0.28 Endymion Sake Mail 1.0.27 Endymion Sake Mail 1.0.26 Endymion Sake Mail 1.0.24 Endymion Sake Mail 1.0.23 Endymion Sake Mail 1.0.22 Endymion Sake Mail 1.0.21 Endymion Sake Mail 1.0.20 |
| Not Vulnerable: | |
Discussion
Endymion Sake Mail Null Character File Disclosure Vulnerability
Endymion Sake Mail is a webmail servlet, written in Java. It will run on most Unix and Linux variants, in addition to Microsoft Windows operating systems.
Endymion Sake Mail is prone to directory traversal attacks, potentially disclosing arbitrary web-readable files to remote attackers. Successful exploitation entails crafting a malicious web request, targetting an arbitrary web-readable file. The malicious request will include dot-dot-slash (../) sequences and a trailing null character (%00).
This issue may cause sensitive information to be disclosed to remote attackers.
Endymion Sake Mail is a webmail servlet, written in Java. It will run on most Unix and Linux variants, in addition to Microsoft Windows operating systems.
Endymion Sake Mail is prone to directory traversal attacks, potentially disclosing arbitrary web-readable files to remote attackers. Successful exploitation entails crafting a malicious web request, targetting an arbitrary web-readable file. The malicious request will include dot-dot-slash (../) sequences and a trailing null character (%00).
This issue may cause sensitive information to be disclosed to remote attackers.
Exploit / POC
Endymion Sake Mail Null Character File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Endymion Sake Mail Null Character File Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Endymion Sake Mail Null Character File Disclosure Vulnerability
References:
References:
- Sake Mail Advisory (FreeFly.Com)
- Sake Mail Homepage (Endymion)