about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IceWarp Web Mail Session ID Disclosure Vulnerability


Title IceWarp Web Mail Session ID Disclosure Vulnerability
Published 2002-02-09-12:00AM
Updated 2004-12-31-09:24PM
Class Design Error
CVE   CAN-2002-0258
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to H?seyin Uslu <raistlinthewiz@hotmail.com>.
Vulnerable  IceWarp Web Mail 3.1.4
IceWarp Web Mail 1.40.10
IceWarp Web Mail 1.40 .00
Not Vulnerable  IceWarp Web Mail 3.3.1
Code   No exploit is required. The following example demonstrates how a malicious user may access another user's account provided they have acquired a valid session ID:

http://www.example.com/view.html?id=[acquired ID]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 03 Dec 2009 05:09:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
gokus sex nwc jony www.lcdyz. www89sezzx autoclose. Farhan-aha global ann www.laba12 www.wanmei www. Video Proxy WWW.sex.30 Office OCX www.522gg. scating autogaller domainspow t761t %252FNucle fuck vedie bignipples Internatio Wild Girls windows fi www.89sex. homesnursi bryan@graf CMS is Fre wwwlivesex azraels FREEXXXFIL www.bnzx.z hospltal.c sx vedio www.tradea sakeela se Www.pk.com news.21315 indie Www.xxx.in www.slin8. Indian se prorat Sex.Pelem. msn space fullsex.co sexgila controlnam im messeng