Cyclonic Webmail Authentication Bypass Vulnerability
BID:9195
Info
Cyclonic Webmail Authentication Bypass Vulnerability
| Bugtraq ID: | 9195 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2003 12:00AM |
| Updated: | Dec 10 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Somers Raf" <[email protected]>. |
| Vulnerable: |
STALLION Networking Cyclonic webmail 4.0 |
| Not Vulnerable: | |
Discussion
Cyclonic Webmail Authentication Bypass Vulnerability
Cyclonic webmail has been reported prone to an authentication bypass vulnerability. The issue exists due to a flaw in the procedure used to authenticate a remote user before Cyclonic webmail scripts are available for perusal/use. It has been reported that the Cyclonic webmail authentication software relies on a remote POP3 server that may be specified by the attacker, to authenticate valid users. As a result of this, an attacker may specify any remote POP3 server that is under the attackers control and thereby gain access to the Cyclonic webmail scripts.
Cyclonic webmail has been reported prone to an authentication bypass vulnerability. The issue exists due to a flaw in the procedure used to authenticate a remote user before Cyclonic webmail scripts are available for perusal/use. It has been reported that the Cyclonic webmail authentication software relies on a remote POP3 server that may be specified by the attacker, to authenticate valid users. As a result of this, an attacker may specify any remote POP3 server that is under the attackers control and thereby gain access to the Cyclonic webmail scripts.
Exploit / POC
Cyclonic Webmail Authentication Bypass Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Cyclonic Webmail Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cyclonic Webmail Authentication Bypass Vulnerability
References:
References:
- Cyclonic Webmail 4 multiple vulnerabilities ("Somers Raf"
)