[] NeoSense

Fastraq Mailtraq 1.1.4 - Multiple Path Vulnerabilities

Author: Slash
type: remote
platform: windows
port: 
date_added: 2000-03-22 
date_updated: 2012-07-20 
verified: 1 
codes: OSVDB-84662 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/1278/info

A remote user may browse any known directory on a host running Fastraq Mailtraq 1.1.4 by making a URL request that includes the '../' string.

In addition, requesting a URL appended with "../" and an unusually long character string will return an error message disclosing the full path of the Mailtraq installation directory.

Directory traversal vulnerability:
http: //target/../../knowndirectory/

Path disclosure vulnerability:
http:&nbsp;//target/../<very long character string>