CommuniGate Pro Webmail会话劫持漏洞

漏洞信息详情

CommuniGate Pro Webmail会话劫持漏洞

漏洞简介

CommuniGate Pro 3.1到4.0.6版本将会话ID发送给图像HTTP请求的参照字段。远程攻击者借助带IMG标签的电子邮件劫持邮件会话,该标签引用了捕获参照页的恶意URL。

漏洞公告

The vendor has addressed this vulnerability in version ‘4.1b2’ of the product. Customers are advised to upgrade and employ ‘UseCookies’ option during configuration of the server.
Stalker Communigate Pro 3.1

Stalker Communigate Pro 3.2 b7

Stalker Communigate Pro 3.2 b5

Stalker Communigate Pro 3.2.4

Stalker Communigate Pro 3.3 b2

Stalker Communigate Pro 3.3 b1

Stalker Communigate Pro 3.3.2

Stalker Communigate Pro 3.4 b3

Stalker Communigate Pro 4.0 b3

Stalker Communigate Pro 4.0 b2

Stalker Communigate Pro 4.0.1

Stalker Communigate Pro 4.0.2

Stalker Communigate Pro 4.0.3

Stalker Communigate Pro 4.0.6

参考网址

来源: BID
名称: 7501
链接:http://www.securityfocus.com/bid/7501

来源: XF
名称: communigate-pro-session-hijacking(11932)
链接:http://xforce.iss.net/xforce/xfdb/11932

来源: BUGTRAQ
名称: 20030504 CommuniGatePro 4.0.6 [EXPLOIT]
链接:http://www.securityfocus.com/archive/1/320438

来源: SREASON
名称: 3290
链接:http://securityreason.com/securityalert/3290

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享