PT-2003-1476 · Sl · Slwebmail+1

David Litchfield

+1

·

Publicado

2003-05-08

·

Atualizado

2016-10-18

·

CVE-2003-0268

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SLWebMail version 3
Description: The issue allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll. This is possible because the error message reveals the path when an invalid request is made.
Recommendations: For SLWebMail version 3, consider restricting access to the WebMailReq.dll until a patch is available to prevent the disclosure of the server's path.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0268

Produtos afetados

Slwebmail
Webmailreq.Dll