IPSwitch IMail Web Calendaring Incomplete Post Denial Of Service Vulnerability
BID:5365
Info
IPSwitch IMail Web Calendaring Incomplete Post Denial Of Service Vulnerability
| Bugtraq ID: | 5365 |
| Class: | Design Error |
| CVE: |
CVE-2002-1077 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Vulnerability discovery credited to <[email protected]>. |
| Vulnerable: |
Ipswitch IMail 7.0.7 Ipswitch IMail 7.0.6 Ipswitch IMail 7.0.5 Ipswitch IMail 7.0.4 Ipswitch IMail 7.0.3 Ipswitch IMail 7.0.2 Ipswitch IMail 7.0.1 Ipswitch IMail 6.4 Ipswitch IMail 6.3 Ipswitch IMail 6.2 Ipswitch IMail 6.1 Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.5 Ipswitch IMail 6.0.4 Ipswitch IMail 6.0.3 Ipswitch IMail 6.0.2 Ipswitch IMail 6.0.1 Ipswitch IMail 6.0 |
| Not Vulnerable: | |
Discussion
IPSwitch IMail Web Calendaring Incomplete Post Denial Of Service Vulnerability
IMail is a commercial email server software package distributed and maintained by Ipswitch, Incorporated. IMail is available for Microsoft Operating Systems.
When a HTTP POST command is made to the web calendaring service on port 8484, and the "content-length:" header field is blank, the service becomes unstable. It has been reported that such a transaction with the service results in a crash of the iwebcal service.
IMail is a commercial email server software package distributed and maintained by Ipswitch, Incorporated. IMail is available for Microsoft Operating Systems.
When a HTTP POST command is made to the web calendaring service on port 8484, and the "content-length:" header field is blank, the service becomes unstable. It has been reported that such a transaction with the service results in a crash of the iwebcal service.
Exploit / POC
IPSwitch IMail Web Calendaring Incomplete Post Denial Of Service Vulnerability
No exploit is required for this vulnerability.
An attacker may exploit this vulnerability by submitting the following request to a vulnerable server:
POST / HTTP/1.0
No exploit is required for this vulnerability.
An attacker may exploit this vulnerability by submitting the following request to a vulnerable server:
POST / HTTP/1.0
References
IPSwitch IMail Web Calendaring Incomplete Post Denial Of Service Vulnerability
References:
References:
- Ipswitch IMail Software Patches and Upgrades (Ipswitch)