CommuniGate Pro Messaging Server Discloses Certain Directory Contents to Remote Users
|
|
SecurityTracker Alert ID: 1004680 |
|
SecurityTracker URL: http://securitytracker.com/id/1004680
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jul 2 2002
|
Impact:
Disclosure of system information, Disclosure of user information
|
Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 4.0b4 and prior versions
|
Description:
An infomation disclosure vulnerability was reported in the CommuniGate Pro mail server. A remote user can view a listing of the current and parent directory of a web user directory.
It is reported that the following URLs will trigger the flaw:
http://[targethost]/.
http://[targethost]/..
The vendor has reportedly been notified.
|
Impact:
A remote user can view certain directories on the server.
|
Solution:
No solution was available at the time of this entry.
The vendor has reportedly indicated that the flaw will be fixed.
|
Vendor URL: www.stalker.com/CommuniGatePro/ (Links to External Site)
|
Cause:
Input validation error
|
Underlying OS:
BeOS, Linux (Any), MacOS, UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 1 Jul 2002 22:56:02 -0700
Subject: CommuniGate Pro directory listings
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Problem:
An anonymous user can see the listing of the current and parent directory of CommuniGatePro WebUser directory.
Vulnerable:
All current versions of CommuniGatePro <= 4.0b4
Details:
You can get the listing of directory by accessing the CommuiGatePro webmail for example http://host.com/. or http://host.com/..
Vendor Response:
"Thanks for telling, we'll fix it.
Fortunately it's not a security hole since there's no write access, the
contents of that directory is of no interest and other directories are not
accessible this way."
-----BEGIN PGP SIGNATURE-----
Version: Hush 2.1
Note: This signature can be verified at https://www.hushtools.com
wl4EARECAB4FAj0hQH0XHGMwcnJlY3QwckBodXNobWFpbC5jb20ACgkQ3UKq03kicjSo
mgCguaeWoJfXGgL+trYOBu09bmB2T5sAn3rQ6LuLftsLd1OlXXhbgETd34Ci
=a0ah
-----END PGP SIGNATURE-----
Communicate in total privacy.
Get your free encrypted email at https://www.hushmail.com/?l=2
Looking for a good deal on a domain name? http://www.hush.com/partners/offers.cgi?id=domainpeople
|
|