vendor:
IMail
by:
SecurityFocus
7.5
CVSS
HIGH
Improper Access Validation
284
CWE
Product Name: IMail
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2000
IMail Web Services File Attachment Vulnerability
Certain versions of IMail do not perform proper access validation, resulting in users being able to attach files resident on the server. The net result of this is users may attach files on the server to which they should have no access. This access is limited to the user privileges which the server is being run as, typically SYSTEM.
Mitigation:
Ensure that proper access validation is performed when allowing users to attach files to emails.