BVRP Software SLWebmail Path Disclosure Vulnerability
BID:7511
Info
BVRP Software SLWebmail Path Disclosure Vulnerability
| Bugtraq ID: | 7511 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2003 12:00AM |
| Updated: | May 07 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to David Litchfield ([email protected]) and Mark Litchfield ([email protected]). |
| Vulnerable: |
BVRP Software SLWebMail 3 |
| Not Vulnerable: | |
Discussion
BVRP Software SLWebmail Path Disclosure Vulnerability
A vulnerability has been reported for SLWebmail that may reveal the physical path information to attackers.
When certain malformed URL requests are sent to certain DLLs, an error message is returned containing the full path to the affected DLL.
A vulnerability has been reported for SLWebmail that may reveal the physical path information to attackers.
When certain malformed URL requests are sent to certain DLLs, an error message is returned containing the full path to the affected DLL.
Exploit / POC
BVRP Software SLWebmail Path Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
BVRP Software SLWebmail Path Disclosure Vulnerability
Solution:
Affected users are advised to contact the vendor for upgrade information.
Solution:
Affected users are advised to contact the vendor for upgrade information.
References
BVRP Software SLWebmail Path Disclosure Vulnerability
References:
References:
- BVRP Software (BVRP Software)
- Multiple Vulnerabilities in SLWebmail ("NGSSoftware Insight Security Research"
)