Mailtraq Remote Directory Traversal Vulnerability
BID:7921
Info
Mailtraq Remote Directory Traversal Vulnerability
| Bugtraq ID: | 7921 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2003 12:00AM |
| Updated: | Jun 16 2003 12:00AM |
| Credit: | Discovery credited to Noam Rathaus. |
| Vulnerable: |
Mailtraq Mailtraq 2.1 .0.1302 |
| Not Vulnerable: | |
Discussion
Mailtraq Remote Directory Traversal Vulnerability
It has been reported that Mailtraq is vulnerable to a remote directory traversal issue. Because of this, an attacker may be able to gain access to files on the local system with the privileges of the Mailtraq server process.
It has been reported that Mailtraq is vulnerable to a remote directory traversal issue. Because of this, an attacker may be able to gain access to files on the local system with the privileges of the Mailtraq server process.
Solution / Fix
Mailtraq Remote Directory Traversal Vulnerability
Solution:
It has been reported that the vendor has stated the following:
Mailtraq is not vulnerable to this problem if it is installed with the default configuration on a standard "box". u can only access paths exposed by the web server.
This information has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the vendor has stated the following:
Mailtraq is not vulnerable to this problem if it is installed with the default configuration on a standard "box". u can only access paths exposed by the web server.
This information has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.