PT-2002-1541 · Instant Web Mail · Instant Web Mail

Publicado

2002-08-12

·

Atualizado

2008-09-05

·

CVE-2002-0490

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Instant Web Mail versions prior to 0.60
Description The issue allows remote attackers to execute arbitrary POP commands via the id parameter in "message.php", or modify certain mail message headers via numerous parameters in "write.php" due to improper filtering of CR/LF sequences.
Recommendations For Instant Web Mail versions prior to 0.60, update to version 0.60 or later to resolve the issue. As a temporary workaround, consider restricting access to the "message.php" and "write.php" scripts until the update is applied. Avoid using the id parameter in "message.php" and numerous parameters in "write.php" until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0490

Produtos afetados

Instant Web Mail