Korean
<< Back
VID 21341
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The BasiliX Webmail installed on the Web server, according to its version number, has a Mail Attachment Disclosure Vulnerability.
BasiliX is a PHP and Internet Messaging Access Protocol (IMAP) based Web mail program that uses the MySQL database server. BasiliX Webmail versions 1.1.0 and earlier are vulnerable to a Mail Attachment Disclosure Vulnerability, caused by a flaw in permissions on the '/tmp/BasiliX' directory, which the copies of E-Mail attachments is stored in. An attacker could view files that have been attached to outgoing mail messages by users of the Webmail system.

* Note: This check solely relied on the version number of the remote BasiliX Webmail to assess this vulnerability, so this might be a false positive.

* References:
http://archives.neohapsis.com/archives/bugtraq/2002-06/0232.html

* Platforms Affected:
Murat Arslan, BasiliX Webmail 1.1.0 and earlier
Unix Any version
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version (1.1.1 or later) of BasiliX Webmail, available from the BasiliX web site at http://sourceforge.net/projects/basilix/
Related URL CVE-2002-1711 (CVE)
Related URL 5065 (SecurityFocus)
Related URL 9387 (ISS)