PT-2001-2345 · Ipswitch · Ipswitch Imail

Published

2001-12-31

·

Updated

2008-09-05

·

CVE-2001-1211

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ipswitch IMail versions 7.0.4 and earlier
Description The issue allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server. This is due to the aliasadmin or listadm1 CGI programs not properly verifying that an administrator is the administrator for the target domain.
Recommendations For Ipswitch IMail versions 7.0.4 and earlier, consider restricting access to the aliasadmin and listadm1 CGI programs until a proper fix is available. As a temporary workaround, ensure that only trusted administrators have access to these programs to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1211

Affected Products

Ipswitch Imail