MailWasher Server LDAP Unauthorized Folder Access Vulnerability

TITLE: MailWasher Server LDAP Unauthorized Folder Access Vulnerability
CLASS: Access Validation Error
CVE:
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 18 2007 12:00AM
UPDATE: Jun 18 2007 12:00AM
CREDIT: The vendor disclosed this issue.
VULNERABLE:

MailWasher Server MailWasher Server 2.2
NOT VULNERABLE:
MailWasher Server MailWasher Server 2.2

Vai alla pagina originale su Security Focus

Discussion

MailWasher Server is prone to a vulnerability that may allow remote attackers to potentially gain access to sensitive data.

This issue affects versions prior to 2.2.1.

Exploit

An exploit is not required.

Solution

Solution:
The vendor has released version 2.2.1 to address this issue.

References

References:

PhpLog

BNLug Benevento Linux Users Group