Family: CGI abuses --> Category: attack
IronWebMail Pathname Reference Directory Traversal Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Tries to read a local file via IronWebMail
Detailed Explanation for this Vulnerability Test
The remote web server is prone to a directory traversal vulnerability.
The remote host appears to be an IronMail appliance, which is intended
to protect enterprise-class email servers from spam, viruses, and
The webmail component of the remote IronMail device does not properly
validate pathname references included in a URL before using them to
return the contents of files on the remote host. An unauthenticated
attacker can leverage this flaw to read arbitrary files and
directories on the remote host.
See also :
Upgrade to Ironmail version 6.1.1 as necessary and install HotFix-17,
as described in the vendor advisory referenced above.
Low / CVSS Base Score : 2
Click HERE for more information and discussions on this network vulnerability scan.