about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IceWarp Web Mail Session ID Disclosure Vulnerability


Title IceWarp Web Mail Session ID Disclosure Vulnerability
Published 2002-02-09-12:00AM
Updated 2004-12-31-09:24PM
Class Design Error
CVE   CAN-2002-0258
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to H?seyin Uslu <raistlinthewiz@hotmail.com>.
Vulnerable  IceWarp Web Mail 3.1.4
IceWarp Web Mail 1.40.10
IceWarp Web Mail 1.40 .00
Not Vulnerable  IceWarp Web Mail 3.3.1
Code   No exploit is required. The following example demonstrates how a malicious user may access another user's account provided they have acquired a valid session ID:

http://www.example.com/view.html?id=[acquired ID]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Mon, 30 Nov 2009 07:57:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
quake 3 Joomla! news for c xoops icon tcp wrappe admin/cont Unauthoriz superbuddy www.indien Tirsa sex www.duduwo www.plooy. sexy indai Msn Messen ABO.CMS IceWarp We PHP+Advanc shahvatsar news for c www.021555 zainykulsm www.ie0551 5.5.12 www.china- vsftpd 2. www.u88hao show powered b www,tamils www.tuijia php-nuke 6 www.201edu Funmaza.Co www,tamils injection www.kn10.c news+for+c axinom sexy vidip gambar art news for C news for C hsoutmix wwwsexanim news for c t831t Crack Data Www.sexwal www.18to 1 womensex c