Family: CGI abuses --> Category: infos
Alt-N WebAdmin Multiple Remote Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary
Checks for the version of Alt-N WebAdmin
Detailed Explanation for this Vulnerability Test
The remote host is running Alt-N WebAdmin, a web interface to MDaemon
The remote version of this software is vulnerable to a cross site
scripting vulnerability due to a lack of filtering on user-supplied
input in the file 'useredit_account.wdm' and the file 'modalframe.wdm'.
A possible hacker may exploit this flaw to steal user credentials.
This software is also vulnerable to a bypass access vulnerability
in the file 'useredit_account.wdm'. A possible hacker may exploit this flaw
to modify user account information.
A possible hacker need a valid email account on the server to exploit both
Solution : Upgrade to WebAdmin 3.0.3.
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.