Reported March 12, 2002, by Obscure.
VERSION AFFECTED
Ipswitch IMail Server version 7.05 and earlier
DESCRIPTION
VENDOR RESPONSE
The
vendor, Ipswitch, has released version 7.06, which resolves this issue.
CREDIT
When a user logs on to his or her account through the IMail Server Web interface, the application uses a unique URL to maintain the session authentication.
By sending an HTML email message that references an image on another server, an attacker can easily obtain the unique URL via the referrer field in the HTTP header.
Discovered by Obscure.
Session Authentication URL Exposed in Ipswitch IMail Server
0 comments
Hide comments