| VID |
21341 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The BasiliX Webmail installed on the Web server, according to its version number, has a Mail Attachment Disclosure Vulnerability. BasiliX is a PHP and Internet Messaging Access Protocol (IMAP) based Web mail program that uses the MySQL database server. BasiliX Webmail versions 1.1.0 and earlier are vulnerable to a Mail Attachment Disclosure Vulnerability, caused by a flaw in permissions on the '/tmp/BasiliX' directory, which the copies of E-Mail attachments is stored in. An attacker could view files that have been attached to outgoing mail messages by users of the Webmail system.
* Note: This check solely relied on the version number of the remote BasiliX Webmail to assess this vulnerability, so this might be a false positive.
* References: http://archives.neohapsis.com/archives/bugtraq/2002-06/0232.html
* Platforms Affected: Murat Arslan, BasiliX Webmail 1.1.0 and earlier Unix Any version Linux Any version Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version (1.1.1 or later) of BasiliX Webmail, available from the BasiliX web site at http://sourceforge.net/projects/basilix/ |
| Related URL |
CVE-2002-1711 (CVE) |
| Related URL |
5065 (SecurityFocus) |
| Related URL |
9387 (ISS) |
|