PostACI Webmail information disclosure vulnerability
3 Dec. 2000
Summary
PostACI (Turkish word for Postman) is a multiplatform GPL'ed webmail software which is database independent (MySQL, PostgreSQL, Sybase, MS SQL), multilingual (Turkish, English, etc), POP3/IMAP and fully MIME compatible. The product contains a security vulnerability that allows remote users to reveal sensitive information about the operating system.
The PostACI webmail system contains a rather trivial vulnerability. It is possible to obtain the hostname, username and password variables for the MySQL server (in addition to other setup information) if PostACI is setup as described running out of the box by simply going to the URL: