|
Family: CGI abuses --> Category: attack
IronWebMail Pathname Reference Directory Traversal Vulnerability Vulnerability Scan
Vulnerability Scan Summary Tries to read a local file via IronWebMail
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server is prone to a directory traversal vulnerability.
Description :
The remote host appears to be an IronMail appliance, which is intended
to protect enterprise-class email servers from spam, viruses, and
hackers.
The webmail component of the remote IronMail device does not properly
validate pathname references included in a URL before using them to
return the contents of files on the remote host. An unauthenticated
attacker can leverage this flaw to read arbitrary files and
directories on the remote host.
See also :
http://www.securityfocus.com/advisories/11308
https://supportcenter.ciphertrust.com/vulnerability/IWM501-01.html
Solution :
Upgrade to Ironmail version 6.1.1 as necessary and install HotFix-17,
as described in the vendor advisory referenced above.
Threat Level:
Low / CVSS Base Score : 2
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|