PT-2008-5088 · Microworld · Mailscan

Publicado

2008-08-20

·

Atualizado

2017-08-08

·

CVE-2008-3728

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MailScan version 5.6.a espatch 1
Description The issue concerns the Web Based Administration in MailScan, where sensitive information is stored under the web root with insufficient access control. This allows remote attackers to obtain sensitive data, including the installation path, IP addresses, and error messages, by making direct requests to files under the LOG/ directory.
Recommendations For MailScan version 5.6.a espatch 1, consider restricting access to the LOG/ directory to minimize the risk of exploitation. As a temporary workaround, limit direct requests to files under this directory until a more permanent solution is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3728

Produtos afetados

Mailscan