PT-2001-1139 · Postaci · Postaci Webmail System

Publicado

2001-01-09

·

Atualizado

2008-09-05

·

CVE-2000-1100

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostACI webmail system (affected versions not specified)
Description The default configuration of the PostACI webmail system allows remote attackers to read sensitive information, including database usernames and passwords, via a direct HTTP GET request to the /includes/global.inc configuration file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-1100

Produtos afetados

Postaci Webmail System