Infinite Mobile Delivery Webmail Multiple Vulnerabilities (XSS, PD)
|
|
Article ID: 16278
Last updated: 27 Jan, 2009
|
|
|
|
Views: 489
|
|
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.
|
|
Infinite Mobile Delivery Webmail Multiple Vulnerabilities (XSS, PD) |
|
| This script is Copyright (C) 2005-2009 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Plugin ID | 16278 |
| Bugtraq ID | 12399
|
| CVE ID | CVE-2005-0323 CVE-2005-0324
|
|
| Description: |
There are flaws in the remote Infinite Mobile Delivery, a web interface
to provide wireless access to mail.
This version of Infinite Mobile Delivery is vulnerable to a cross site
scripting vulnerability and to a path disclosure vulnerability.
An attacker, exploiting this flaw, would be able to steal user credentials
or use disclosed information to launch further attacks.
Solution: None at this time
Risk factor : Medium |
|