PT-2001-2345 · Ipswitch · Ipswitch Imail

Publicado

2001-12-31

·

Atualizado

2008-09-05

·

CVE-2001-1211

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ipswitch IMail versions 7.0.4 and earlier
Description The issue allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server. This is due to the aliasadmin or listadm1 CGI programs not properly verifying that an administrator is the administrator for the target domain.
Recommendations For Ipswitch IMail versions 7.0.4 and earlier, consider restricting access to the aliasadmin and listadm1 CGI programs until a proper fix is available. As a temporary workaround, ensure that only trusted administrators have access to these programs to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1211

Produtos afetados

Ipswitch Imail