PT-2004-3463 · Amax · Amax Magic Winmail Server
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2572
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AMAX Magic Winmail Server version 3.6
Description
The issue allows remote attackers to obtain sensitive information by entering invalid characters, such as
(), or a large number of characters in the "Lookup" field on the "netaddressbook.php" web form. This reveals the path in an "ldaplib.php" error message when the ldap search function fails due to improper processing of the $keyword variable.Recommendations
For AMAX Magic Winmail Server version 3.6, consider restricting input in the "Lookup" field on the "netaddressbook.php" web form to prevent the entry of invalid or excessive characters, and ensure proper validation and sanitization of the
$keyword variable to prevent information disclosure.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amax Magic Winmail Server