[] NeoSense

ironwebmail 6.1.1 - Directory Traversal Information Disclosure

Author: Derek Callaway
type: webapps
platform: php
port: 
date_added: 2006-10-16 
date_updated: 2013-10-07 
verified: 1 
codes: CVE-2006-5210;OSVDB-29755 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/20436/info

IronWebMail is prone to a remote information-disclosure vulnerability because the application fails to properly sanitize user-supplied input.

Exploiting this issue allows remote, unauthenticated attackers to retrieve the contents of arbitrary files from vulnerable computers with the privileges of the webserver process. Information harvested may aid in further attacks.

IronWebMail versions prior to 6.1.1 HotFix-17 are affected by this vulnerability.

GET /IM_FILE(%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/admin.xml) HTTP/1.0[CRLF][CRLF]