Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: CGI abuses --> Category: infos

Ingo Foldername Command Execution Vulnerability Vulnerability Scan


Vulnerability Scan Summary
Checks version number of Ingo

Detailed Explanation for this Vulnerability Test

Synopsis :

The remote web server contains a PHP script that is affected by a
command execution vulnerability.

Description :

According to its version number, the instance of Ingo installed on the
remote host fails to properly sanitize mailbox destinations in filter
rules. By using a folder name beginning with '|' as a mailbox
destination, an authenticated remote attacker may be able to exploit
this issue to execute arbitrary code on the remote host, subject to
the permissions of the web server user id.

See also :

http://bugs.horde.org/ticket/?id=4513
http://lists.horde.org/archives/announce/2006/000296.html

Solution :

Upgrade to Ingo version H3 (1.1.2) or later.

Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N)

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.