漏洞信息详情
Trlinux Postaci Webmail 密码泄漏漏洞
- CNNVD编号:CNNVD-200101-012
- 危害等级: 高危
- CVE编号:
CVE-2000-1100
- 漏洞类型:
访问验证错误
- 发布时间:
2001-01-09
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
trlinux - 漏洞来源:
Discovered and pos… -
漏洞简介
PostACI web邮件系统默认配置安装web根目录的/includes/global.inc配置文件。远程攻击者可以借助直接HTTP GET请求读取如数据库用户名和密码的敏感信息。
漏洞公告
This was sent from Lars Christian Nygård
This should not be possible if you follow the installation instructions properly and add the .inc extension to the AddHandle/Addtype in apache. This IS described and pointed out in the ../doc/INSTALL document of Postaci as crucial for security.
参考网址
来源: BID
名称: 2029
链接:http://www.securityfocus.com/bid/2029
来源: BUGTRAQ
名称: 20001130 PostACI Webmail Vulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2000-11/0433.html
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END