SqWebMail Session Hijacking Vulnerability
BID:9058
Info
SqWebMail Session Hijacking Vulnerability
| Bugtraq ID: | 9058 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2003 12:00AM |
| Updated: | Nov 17 2003 12:00AM |
| Credit: | Discovery is credited to Vincenzo Ciaglia <[email protected]>. |
| Vulnerable: |
Inter7 SqWebMail 3.6.1 Inter7 SqWebMail 3.6 .0 Inter7 SqWebMail 3.5.3 Inter7 SqWebMail 3.5.2 Inter7 SqWebMail 3.5.1 Inter7 SqWebMail 3.5 .0 Inter7 SqWebMail 3.4.1 Double Precision Incorporated Courier MTA 0.40.1 Double Precision Incorporated Courier MTA 0.40 Double Precision Incorporated Courier MTA 0.38.1 Double Precision Incorporated Courier MTA 0.37.3 |
| Not Vulnerable: | |
Discussion
SqWebMail Session Hijacking Vulnerability
SqWebMail is prone to a vulnerability that may allow remote attackers to hijack webmail sessions. This vulnerability occurs if the victim user follows a malicious link provided by an attacker via an e-mail that is viewed from the webmail system. This will permit an attacker to gain unauthorized access to the user's session ID, which may be then used to hijack the user's session, if it hasn't timed out.
SqWebMail is included in the Courier mail server, but is also available as a stand-alone CGI application.
SqWebMail is prone to a vulnerability that may allow remote attackers to hijack webmail sessions. This vulnerability occurs if the victim user follows a malicious link provided by an attacker via an e-mail that is viewed from the webmail system. This will permit an attacker to gain unauthorized access to the user's session ID, which may be then used to hijack the user's session, if it hasn't timed out.
SqWebMail is included in the Courier mail server, but is also available as a stand-alone CGI application.
Exploit / POC
SqWebMail Session Hijacking Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
SqWebMail Session Hijacking Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SqWebMail Session Hijacking Vulnerability
References:
References:
- SqWebMail Homepage (Inter7)
- PCL-0002: Session Hijacking in "Sqwebmail" (Vincenzo Ciaglia
)