RSS   Vulnerabilities for 'Mailscan'   RSS

2008-08-20
 
CVE-2008-3729

CWE-287
 

 
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or (2) no cookie.

 
 
CVE-2008-3728

CWE-264
 

 
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to determine the installation path, IP addresses, and error messages via direct requests to files under LOG/.

 
 
CVE-2008-3727

CWE-22
 

 
Directory traversal vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

 
 
CVE-2008-3726

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to inject arbitrary web script or HTML via the URI.

 

 >>> Vendor: Microworld technologies 7 Products
Escan
Escan anti-virus
Escan internet security
Escan virus control
Escan management console
Escan server
Mailscan


Copyright 2024, cxsecurity.com

 

Back to Top