Family: CGI abuses --> Category: infos
IlohaMail Contacts Deletion Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Checks for Contacts Deletion vulnerability in IlohaMail
Detailed Explanation for this Vulnerability Test
The target is running at least one instance of IlohaMail version
0.7.9-RC2 or earlier. Such versions contain a flaw that enables an
authenticated user to delete contacts belonging to any user provided
the DB-based backend is used to store contacts. The flaw arises
because ownership of 'delete_item' is not checked when deleting
entries in include/save_contacts.MySQL.inc.
***** Nessus has acertaind the vulnerability exists on the target
***** simply by looking at the version number of IlohaMail
***** installed there.
Solution : Upgrade to IlohaMail version 0.7.9 or later.
Threat Level: Low
Click HERE for more information and discussions on this network vulnerability scan.