Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Remote file access >> IlohaMail Readable Configuration Files


Vulnerability Assessment Details

IlohaMail Readable Configuration Files

Vulnerability Assessment Summary
Checks for Readable Configuration Files in IlohaMail

Detailed Explanation for this Vulnerability Assessment

The target is running at least one instance of IlohaMail that permits
anyone to retrieve its configuration files over the web. These files
may contain sensitive information. For example, conf/conf.inc may
hold a username / password used for SMTP authentication.

Solution : Upgrade to IlohaMail version 0.8.14-rc2 or later or
reinstall following the 'Proper Installation' instructions in the
INSTALL document.

Network Security Threat Level: Medium

Networks Security ID: 12252

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 George A. Theall

Cables, Connectors

Cisco WS-C3750X-12S-S Catalyst 12-Port Gigabit SFP Port Switch w/ 1x 350W PS
$309.0
Cisco WS-C3750X-12S-S Catalyst 12-Port Gigabit SFP Port Switch w/ 1x 350W PS picture10-Pack 10G SFP+ DAC Cable 10GBASE-CU Passive Direct Attach Copper Twinax For 1m
$165.21
10-Pack 10G SFP+ DAC Cable 10GBASE-CU Passive Direct Attach Copper Twinax For 1m pictureCisco WS-C2960S-24PS-L Catalyst 2960S Stack 24 GigE PoE 370W, 4 x SFP LAN Base
$175.0
Cisco WS-C2960S-24PS-L Catalyst 2960S Stack 24 GigE PoE 370W, 4 x SFP LAN Base  pictureNew Meraki MS320-48FP MS350 Full PoE Unclaimed Cloud Managed 48 Port SFP+
$1995.0
New Meraki MS320-48FP MS350 Full PoE Unclaimed Cloud Managed 48 Port SFP+ picture


Discussions

No Discussions have been posted on this vulnerability.