CVE Vulnerabilities

CVE-2001-1286

Published: Oct 12, 2001 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Ipswitch IMail 7.04 and earlier stores a users session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attackers control.

Affected Software

Name Vendor Start Version End Version
Imail Ipswitch 6.0.2 (including) 6.0.2 (including)
Imail Ipswitch 6.0.6 (including) 6.0.6 (including)
Imail Ipswitch 7.0.4 (including) 7.0.4 (including)

References