Session Authentication URL Exposed in Ipswitch IMail Server

Reported March 12, 2002, by Obscure.

VERSION AFFECTED

  • Ipswitch IMail Server version 7.05 and earlier

DESCRIPTION
When a user logs on to his or her account through the IMail Server Web interface, the application uses a unique URL to maintain the session authentication. By sending an HTML email message that references an image on another server, an attacker can easily obtain the unique URL via the referrer field in the HTTP header.


VENDOR RESPONSE

The vendor, Ipswitch, has released version 7.06, which resolves this issue.


CREDIT
Discovered by Obscure.

TAGS: Security
Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish