PT-2003-1476 · Sl · Slwebmail+1
David Litchfield
+1
·
Published
2003-05-08
·
Updated
2016-10-18
·
CVE-2003-0268
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SLWebMail version 3
Description:
The issue allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll. This is possible because the error message reveals the path when an invalid request is made.
Recommendations:
For SLWebMail version 3, consider restricting access to the WebMailReq.dll until a patch is available to prevent the disclosure of the server's path.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Slwebmail
Webmailreq.Dll