PT-2008-4489 · V Webmail · V-Webmail

Publicado

2008-10-07

·

Atualizado

2017-08-08

·

CVE-2008-3060

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: V-webmail version 1.5.0
Description: The issue allows remote attackers to obtain sensitive information. This can be achieved through malformed input in the login page, which includes the local.hooks.php file, or by using an invalid session ID. The latter reveals the installation path in an error message.
Recommendations: For V-webmail version 1.5.0, consider validating and sanitizing all user input to prevent malformed data from being processed, and implement proper error handling to avoid revealing sensitive information such as the installation path. Additionally, restrict access to error messages that could disclose sensitive details.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3060

Produtos afetados

V-Webmail