PT-2003-1476 · Sl · Slwebmail+1

David Litchfield

+1

·

Published

2003-05-08

·

Updated

2016-10-18

·

CVE-2003-0268

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SLWebMail version 3
Description: The issue allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll. This is possible because the error message reveals the path when an invalid request is made.
Recommendations: For SLWebMail version 3, consider restricting access to the WebMailReq.dll until a patch is available to prevent the disclosure of the server's path.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0268

Affected Products

Slwebmail
Webmailreq.Dll