Vulnwatch mailing list archives
Multiple Vulnerabilities Found in Mailtraq (DoS, Password Decryption, Directory Traversal)
From: "SecurITeam BugTraq Monitoring" <bugtraq () securiteam com>
Date: Mon, 16 Jun 2003 11:31:27 +0200
Summary: Mailtraq is a "comprehensive e-mail SMTP/POP3 and proxy server, with a powerful mailing list server". The product suffeed from multiple vulnerabilities that range from access to files that reside outside the bounding HTML root directory (through dnying access to the server by causing the server to utilize a high CPU percentage) through decryption of locally stored password, to a cross site scripting vulnerability in the web mail interface. Vulnerable version: * Mailtraq version 2.1.0.1302 Immune version: * Mailtraq version 2.3.2.1419 For the complete advisory see: http://www.securiteam.com/windowsntfocus/5HP0G1FAAC.html Thanks SecurITeam http://www.SecurITeam.com http://www.BeyondSecurity.com
Current thread:
- Multiple Vulnerabilities Found in Mailtraq (DoS, Password Decryption, Directory Traversal) SecurITeam BugTraq Monitoring (Jun 16)