vendor:
CommuniGatePro
by:
Yaroslav Polyakov
7.5
CVSS
HIGH
Session Hijacking, Mail Downloading
CWE
Product Name: CommuniGatePro
Affected Version From: CommuniGatePro 4.0.6
Affected Version To: CommuniGatePro 4.0.6
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Session Hijacking and Mail Downloading Exploit for CommuniGatePro 4.0.6
This exploit code allows an attacker to hijack a session and download messages from the victim's mailbox in CommuniGatePro 4.0.6. The attacker needs to place the exploit code in the cgi-bin and configure the necessary variables. They can then send a victim an HTML message with an image source pointing to AnyImage.gif. When the victim reads the message, the script will download messages 1 to 10 from their mailbox.
Mitigation:
Upgrade to a newer version of CommuniGatePro that addresses this vulnerability. Additionally, ensure that users are educated about the risks of opening suspicious emails or clicking on unknown links.