Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IceWarp Web Mail Session ID Disclosure Vulnerability

IceWarp Web Mail is reported to be affected by a vulnerability related to session ID handling. The cause of the issue is that session IDs may be included in 'answer' and 'forward' link in email responses, exposing the session ID to other user's of the Web mail system.

This issue may be exploited to hijack a user's session.







 

Privacy Statement
Copyright 2008, SecurityFocus