Fastraq Mailtraq 1.1.4 - Multiple Path Vulnerabilities

Author: Slash
type: remote
platform: windows
port: 
date_added: 2000-03-22
date_updated: 2012-07-20
verified: 1
codes: OSVDB-84662
tags: 
aliases: 
screenshot_url: 
application_url: 

source: https://www.securityfocus.com/bid/1278/info

A remote user may browse any known directory on a host running Fastraq Mailtraq 1.1.4 by making a URL request that includes the '../' string.

In addition, requesting a URL appended with "../" and an unusually long character string will return an error message disclosing the full path of the Mailtraq installation directory.

Directory traversal vulnerability:
http: //target/../../knowndirectory/

Path disclosure vulnerability:
http:&nbsp;//target/../<very long character string>