Instant Web Mail POP Command Execution Vulnerability
BID:4361
Info
Instant Web Mail POP Command Execution Vulnerability
| Bugtraq ID: | 4361 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2002 12:00AM |
| Updated: | Mar 23 2002 12:00AM |
| Credit: | Credited to Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
Instant Web Mail Instant Web Mail 0.59 Instant Web Mail Instant Web Mail 0.58 Instant Web Mail Instant Web Mail 0.57 Instant Web Mail Instant Web Mail 0.56 Instant Web Mail Instant Web Mail 0.55 |
| Not Vulnerable: |
Instant Web Mail Instant Web Mail 0.60 |
Discussion
Instant Web Mail POP Command Execution Vulnerability
Instant Web Mail is a free, web based POP email client. It is implemented in PHP, and can be expected to run under Windows, Linux and most Unix systems.
A vulnerability has been reported in some versions of Instant Web Mail. An attacker may create links to vulnerable scripts including arbitrary POP commands, and send email including these links to a user of the system. If the link is followed, the command will be executed.
Instant Web Mail is a free, web based POP email client. It is implemented in PHP, and can be expected to run under Windows, Linux and most Unix systems.
A vulnerability has been reported in some versions of Instant Web Mail. An attacker may create links to vulnerable scripts including arbitrary POP commands, and send email including these links to a user of the system. If the link is followed, the command will be executed.
Exploit / POC
Instant Web Mail POP Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Instant Web Mail POP Command Execution Vulnerability
Solution:
An updated version is available:
Instant Web Mail Instant Web Mail 0.55
Instant Web Mail Instant Web Mail 0.56
Instant Web Mail Instant Web Mail 0.57
Instant Web Mail Instant Web Mail 0.58
Instant Web Mail Instant Web Mail 0.59
Solution:
An updated version is available:
Instant Web Mail Instant Web Mail 0.55
-
Instant Web Mail instantwebmail.tar.bz2
http://understroem.dk/instantwebmail/instantwebmail.tar.bz2
Instant Web Mail Instant Web Mail 0.56
-
Instant Web Mail instantwebmail.tar.bz2
http://understroem.dk/instantwebmail/instantwebmail.tar.bz2
Instant Web Mail Instant Web Mail 0.57
-
Instant Web Mail instantwebmail.tar.bz2
http://understroem.dk/instantwebmail/instantwebmail.tar.bz2
Instant Web Mail Instant Web Mail 0.58
-
Instant Web Mail instantwebmail.tar.bz2
http://understroem.dk/instantwebmail/instantwebmail.tar.bz2
Instant Web Mail Instant Web Mail 0.59
-
Instant Web Mail instantwebmail.tar.bz2
http://understroem.dk/instantwebmail/instantwebmail.tar.bz2
References
Instant Web Mail POP Command Execution Vulnerability
References:
References:
- Instant Web Mail Homepage (Understrøm)