PT-2004-3463 · Amax · Amax Magic Winmail Server

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2572

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions AMAX Magic Winmail Server version 3.6
Description The issue allows remote attackers to obtain sensitive information by entering invalid characters, such as (), or a large number of characters in the "Lookup" field on the "netaddressbook.php" web form. This reveals the path in an "ldaplib.php" error message when the ldap search function fails due to improper processing of the $keyword variable.
Recommendations For AMAX Magic Winmail Server version 3.6, consider restricting input in the "Lookup" field on the "netaddressbook.php" web form to prevent the entry of invalid or excessive characters, and ensure proper validation and sanitization of the $keyword variable to prevent information disclosure.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2572

Affected Products

Amax Magic Winmail Server