Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Winmail Mail Server Information Disclosure


Vulnerability Assessment Details

Winmail Mail Server Information Disclosure

Vulnerability Assessment Summary
Searches for the existence of an Information Disclosure in Winmail Mail Server

Detailed Explanation for this Vulnerability Assessment

The remote host is running Winmail Server.

Winmail Server is an enterprise class mail server software system
offering a robust feature set, including extensive security
measures. Winmail Server supports SMTP, POP3, IMAP, Webmail, LDAP,
multiple domains, SMTP authentication, spam protection, anti-virus
protection, SSL/TLS security, Network Storage, remote access,
Web-based administration, and a wide array of standard email options
such as filtering, signatures, real-time monitoring, archiving,
and public email folders.

Three scripts that come with the program (chgpwd.php, domain.php and user.php)
permit a remote attacker to disclose sensitive information about the remote host.

Solution : Upgrade to the latest version of this software
Network Security Threat Level: Medium

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Noam Rathaus

Cables, Connectors


Hayes Vintage Chronograph RS232C Rare picture

Hayes Vintage Chronograph RS232C Rare

$600.00



Vintage Quake 3 mouse pad picture

Vintage Quake 3 mouse pad

$9.99



Vintage Compaq 141649-004 2 Button PS/2 Gray Mouse M-S34 - FAST SHIPPING - NEW picture

Vintage Compaq 141649-004 2 Button PS/2 Gray Mouse M-S34 - FAST SHIPPING - NEW

$8.99



Drakware ADB2USB - vintage Apple ADB to USB keyboard adapter picture

Drakware ADB2USB - vintage Apple ADB to USB keyboard adapter

$29.95



Vintage Classic Apple Macintosh System Boot Install Disk Floppy/CD *Pick Version picture

Vintage Classic Apple Macintosh System Boot Install Disk Floppy/CD *Pick Version

$10.39



Voltage Blaster (Enhanced) -5V ISA AT ATX Power for Vintage Retro PCs US Seller picture

Voltage Blaster (Enhanced) -5V ISA AT ATX Power for Vintage Retro PCs US Seller

$12.95



Vintage Black Microsoft intellimouse Optical USB Wheel Mouse 1.1/1.1a - EXC COND picture

Vintage Black Microsoft intellimouse Optical USB Wheel Mouse 1.1/1.1a - EXC COND

$28.95



Vintage 1992 Hewlett Packard HP 200LX Palmtop PC 2MB picture

Vintage 1992 Hewlett Packard HP 200LX Palmtop PC 2MB

$175.00



Vintage Comfort Keyboard Systems Ergomagic Mechanical AT/PS2 Keyboard picture

Vintage Comfort Keyboard Systems Ergomagic Mechanical AT/PS2 Keyboard

$149.99



Vintage scorpius 980n plus Mechanical USB keyboard picture

Vintage scorpius 980n plus Mechanical USB keyboard

$39.00



Discussions

No Discussions have been posted on this vulnerability.