Family: CGI abuses --> Category: infos

IlohaMail Contacts Deletion Vulnerability Vulnerability Scan

Vulnerability Scan Summary
Checks for Contacts Deletion vulnerability in IlohaMail

Detailed Explanation for this Vulnerability Test

The target is running at least one instance of IlohaMail version
0.7.9-RC2 or earlier. Such versions contain a flaw that enables an
authenticated user to delete contacts belonging to any user provided
the DB-based backend is used to store contacts. The flaw arises
because ownership of 'delete_item' is not checked when deleting
entries in include/

***** Nessus has acertaind the vulnerability exists on the target
***** simply by looking at the version number of IlohaMail
***** installed there.

Solution : Upgrade to IlohaMail version 0.7.9 or later.

Threat Level: Low

