PT-2001-1139 · Postaci · Postaci Webmail System

Published

2001-01-09

·

Updated

2008-09-05

·

CVE-2000-1100

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostACI webmail system (affected versions not specified)
Description The default configuration of the PostACI webmail system allows remote attackers to read sensitive information, including database usernames and passwords, via a direct HTTP GET request to the /includes/global.inc configuration file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1100

Affected Products

Postaci Webmail System