Fastraq Mailtraq 1.1.4 - Multiple Path Vulnerabilities
Author: Slash
type: remote
platform: windows
port:
date_added: 2000-03-22
date_updated: 2012-07-20
verified: 1
codes: OSVDB-84662
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/1278/info
A remote user may browse any known directory on a host running Fastraq Mailtraq 1.1.4 by making a URL request that includes the '../' string.
In addition, requesting a URL appended with "../" and an unusually long character string will return an error message disclosing the full path of the Mailtraq installation directory.
Directory traversal vulnerability:
http: //target/../../knowndirectory/
Path disclosure vulnerability:
http: //target/../<very long character string>