Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability
BID:9781
Info
Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability
| Bugtraq ID: | 9781 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2004 12:00AM |
| Updated: | Mar 01 2004 12:00AM |
| Credit: | Disclosure of this issue has been credited to Rafel Ivgi, The-Insider <[email protected]> |
| Vulnerable: |
Software602 602Pro LAN SUITE 2003 Software602 602Pro LAN SUITE 2002 |
| Not Vulnerable: |
Software602 602 Pro LAN SUITE 2004 |
Discussion
Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability
It has been reported that 602Pro LAN SUITE is prone to a remote installation path disclosure vulnerability. This issue is due to the existence of a hidden parameter embedded within the 'login' form that specifies the installation path.
Successful exploitation of this issue may allow an attacker to gain sensitive information about the file system that may aid in launching more direct attacks against the system.
It has been reported that 602Pro LAN SUITE is prone to a remote installation path disclosure vulnerability. This issue is due to the existence of a hidden parameter embedded within the 'login' form that specifies the installation path.
Successful exploitation of this issue may allow an attacker to gain sensitive information about the file system that may aid in launching more direct attacks against the system.
Exploit / POC
Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability
No exploit is required to exploit this issue.
No exploit is required to exploit this issue.
Solution / Fix
Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability
Solution:
The vendor has released 602LAN SUITE 2004 to address this issue:
Software602 602Pro LAN SUITE 2002
Software602 602Pro LAN SUITE 2003
Solution:
The vendor has released 602LAN SUITE 2004 to address this issue:
Software602 602Pro LAN SUITE 2002
-
Software602 602 LAN Suite 2004
http://www.software602.com/download/
Software602 602Pro LAN SUITE 2003
-
Software602 602 LAN Suite 2004
http://www.software602.com/download/
References
Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability
References:
References:
- 602Pro LAN SUITE Product Page (Software602)
- LAN SUITE Web Mail (Rafel Ivgi, The-Insider
) - Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities (Brandon Sturgeon
)