PT-2000-1649 · Alt N Technologies · Mdaemon

Publicado

2000-10-20

·

Atualizado

2017-10-10

·

CVE-2000-0716

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MDaemon version 2.8
Description The issue concerns the WorldClient email client in MDaemon, where the session ID is included in the referer field of an HTTP request when a user clicks on a URL. This allows the visited website to potentially hijack the session ID and access the user's email.
Recommendations For MDaemon version 2.8, consider restricting access to external URLs from within the email client to minimize the risk of session ID hijacking until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0716

Produtos afetados

Mdaemon