|
Ipswitch IMail Server Multiple Vulnerabilities
The following proof of concept for the directory-traversal issue is available: GET /bla.jsp?\..\..\..\..\..\..\..\..\..\..\boot.ini HTTP/1.0 An exploit targeting the 'username' parameter of the LOGIN command has been provided by <nolimit@coreiso.org>. Another exploit (imail.pl) targeting the LOGIN command has been provided by kcope. An exploit (13727.c) targeted the LOGIN command is available by Heretic2. |
|
Privacy Statement |