CasecadeSoft W3Mail Attachment Exposure Vulnerability
BID:5314
Info
CasecadeSoft W3Mail Attachment Exposure Vulnerability
| Bugtraq ID: | 5314 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2002 12:00AM |
| Updated: | Jul 25 2002 12:00AM |
| Credit: | Published by Tim Brown <[email protected]>. |
| Vulnerable: |
CascadeSoft W3Mail 1.0.5 CascadeSoft W3Mail 1.0.4 CascadeSoft W3Mail 1.0.3 CascadeSoft W3Mail 1.0.2 |
| Not Vulnerable: | |
Discussion
CasecadeSoft W3Mail Attachment Exposure Vulnerability
A vulnerability has been reported in W3Mail that may result in the disclosure of user email attachments. When attachments are uploaded, they are stored in a directory within the webroot. There is no default index file created. If the webserver is configured to output the index of directories, remote clients may view and retrieve attachment files without authorization.
Reportedly, versions of W3Mail prior to 1.0.3 do not properly delete these files when the webmail user logs off, widening the window of opportunity for an attacker.
A vulnerability has been reported in W3Mail that may result in the disclosure of user email attachments. When attachments are uploaded, they are stored in a directory within the webroot. There is no default index file created. If the webserver is configured to output the index of directories, remote clients may view and retrieve attachment files without authorization.
Reportedly, versions of W3Mail prior to 1.0.3 do not properly delete these files when the webmail user logs off, widening the window of opportunity for an attacker.
Exploit / POC
CasecadeSoft W3Mail Attachment Exposure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
CasecadeSoft W3Mail Attachment Exposure Vulnerability
Solution:
Upgrade to version 1.0.6.
Solution:
Upgrade to version 1.0.6.