about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IceWarp Web Mail Session ID Disclosure Vulnerability


Title IceWarp Web Mail Session ID Disclosure Vulnerability
Published 2002-02-09-12:00AM
Updated 2004-12-31-09:24PM
Class Design Error
CVE   CAN-2002-0258
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to H?seyin Uslu <raistlinthewiz@hotmail.com>.
Vulnerable  IceWarp Web Mail 3.1.4
IceWarp Web Mail 1.40.10
IceWarp Web Mail 1.40 .00
Not Vulnerable  IceWarp Web Mail 3.3.1
Code   No exploit is required. The following example demonstrates how a malicious user may access another user's account provided they have acquired a valid session ID:

http://www.example.com/view.html?id=[acquired ID]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 04:42:22 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
java socke Sex+videio shelpashet t514t 200 /compo xxxx+ sex-pics sphinx CMS is Fre shelpashet woman+sex. Arab porno news for c 200 /compo WWW.Sexwor wwwindiani sixe gril Www.Video Gadis bugi Foto2ngent www.bbcper news for c ifilm ip board 2 webclient sex ocean. www.xxx.co xxx.fr rende Lovlypussy Nude scand glitemflat www.94shw. webshell redio low freewebsho 200 /compo 200 /compo www.daohan free india di-604 Aciedo xex Asinsex apache2.x Naked+bbw+ Asinsex t474t sibel.keki aunty hot