EmuMail Web Root Path Disclosure Vulnerability
BID:5823
Info
EmuMail Web Root Path Disclosure Vulnerability
| Bugtraq ID: | 5823 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1527 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to FVS <[email protected]>. |
| Vulnerable: |
EMUMail EMUMail for Windows 5.0 EMUMail EMUMail for Unix 5.0 EMUMail EMUMail for Red Hat Linux 5.0 |
| Not Vulnerable: | |
Discussion
EmuMail Web Root Path Disclosure Vulnerability
Emumail is an open source web mail application. It is available for the Unix, Linux, and Microsoft Windows operating systems.
Under some conditions, Emumail may reveal sensitive configuration information. When unexpected characters are inserted into some fields in web mail forms, the form generates an error. The error page returned may contain the directory to the web root on the Emumail server.
Emumail is an open source web mail application. It is available for the Unix, Linux, and Microsoft Windows operating systems.
Under some conditions, Emumail may reveal sensitive configuration information. When unexpected characters are inserted into some fields in web mail forms, the form generates an error. The error page returned may contain the directory to the web root on the Emumail server.
Exploit / POC
EmuMail Web Root Path Disclosure Vulnerability
Contributed by FVS <[email protected]>:
By inserting a string such into the Email form:
<script>alert(@)</script>
Will return:
"Software error:
/\s+)my.com)</script>\s+/: unmatched () in regexp at /home/EMU/webmail/html/emumail.cgi line 834.
Contributed by FVS <[email protected]>:
By inserting a string such into the Email form:
<script>alert(@)</script>
Will return:
"Software error:
/\s+)my.com)</script>\s+/: unmatched () in regexp at /home/EMU/webmail/html/emumail.cgi line 834.
Solution / Fix
EmuMail Web Root Path Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.