Brought to you by:
Suppliers of:
Open WebMail is a perl web mail program that runs on UNIX operational systems. A vulnerability in the product allows remote attackers to reveal the user who is running the Open WebMail process.
Credit:
The information has been provided by FreeBSDbr Bugtraq DataBase .
Vulnerable systems:
* Open WebMail version 1.71
When you enter an invalid username (user that doesn't exist on the system), the WebMail returns to you a "very nice screen" like it:
---
Open WebMail ERROR
user does not exist
Open WebMail version 1.71
---
Now if you try to copy the information with your mouse all message that returned to you...
---
Open WebMail ERROR
user does not exist
euid=0, egid=80 80 80, mailgid=6
Open WebMail version 1.71
---
As can be seen, very sensitive information regarding the program is revealed.
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by