漏洞信息详情
CommuniGate Pro Webmail会话劫持漏洞
- CNNVD编号:CNNVD-200312-077
- 危害等级: 中危
- CVE编号:
CVE-2003-1481
- 漏洞类型:
信息泄露
- 发布时间:
2003-12-31
- 威胁类型:
远程
- 更新时间:
2003-12-31
- 厂 商:
stalker - 漏洞来源:
Discovery of this … -
漏洞简介
CommuniGate Pro 3.1到4.0.6版本将会话ID发送给图像HTTP请求的参照字段。远程攻击者借助带IMG标签的电子邮件劫持邮件会话,该标签引用了捕获参照页的恶意URL。
漏洞公告
The vendor has addressed this vulnerability in version ‘4.1b2’ of the product. Customers are advised to upgrade and employ ‘UseCookies’ option during configuration of the server.
Stalker Communigate Pro 3.1
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 3.2 b7
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 3.2 b5
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 3.2.4
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 3.3 b2
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 3.3 b1
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 3.3.2
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 3.4 b3
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 4.0 b3
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 4.0 b2
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 4.0.1
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 4.0.2
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 4.0.3
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
Stalker Communigate Pro 4.0.6
-
Stalker CommuniGate Pro 4.0.1b2
http://www.stalker.com/download.html
参考网址
来源: BID
名称: 7501
链接:http://www.securityfocus.com/bid/7501
来源: XF
名称: communigate-pro-session-hijacking(11932)
链接:http://xforce.iss.net/xforce/xfdb/11932
来源: BUGTRAQ
名称: 20030504 CommuniGatePro 4.0.6 [EXPLOIT]
链接:http://www.securityfocus.com/archive/1/320438
来源: SREASON
名称: 3290
链接:http://securityreason.com/securityalert/3290