|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> TIPS MailPost Multiple Flaws Vulnerability Assessment Details
|
TIPS MailPost Multiple Flaws |
||
|
Test the remote mailpost.exe Detailed Explanation for this Vulnerability Assessment The remote host is using a version of TIPS MailPost which is vulnerable to several flaws. TIPS MailPost is an HTML form content email application designed to facilitate the emailing of HTML form data to a third party. There are various flaws in the remote version of this software : - A remote file enumeration vulnerability which may permit a possible hacker to acertain if a file exists or not - Two cross site scripting vulnerabilities which may permit a possible hacker to steal the cookies of third-parties users - An information disclosure vulnerability which may permit a possible hacker to gain more information about the remote host Solution : upgrade your software or protect it with a filtering reverse proxy Network Security Threat Level: Medium Networks Security ID: 11595, 11596, 11598, 11599 Vulnerability Assessment Copyright: This script is Copyright (C) 2004-2007 Tenable Network Security |
||
|
UPS, Power Protection, APC |
|
||
|
No Discussions have been posted on this vulnerability. |