NetWin (1) SurgeMail prima 2.0c e (2) WebMail consentire ad aggressori remoti di ottenere informazioni sensibili tramite richieste HTTP che (a) specificare la / URI, (b) specificare la / scripts / URI, o (c) specificare un non- il file esistente, che rivelano il percorso in un messaggio di errore. |
http://www.securityfocus.com/bid/10483 http://www.netwinsite.com/surgemail/help/updates.htm http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0056.html http://www.exploitlabs.com/files/advisories/EXPL-A-2004-002-surgmail.txt http://www.osvdb.org/6745 http://secunia.com/advisories/11772 https://exchange.xforce.ibmcloud.com/vulnerabilities/16319 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2547 |
Vulnerabilità: CVE-2004-2547
