Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.14305
Category:Web application abuses
Title:BasiliX Arbitrary File Disclosure Vulnerability
Summary:The remote web server contains a PHP script that is prone to information;disclosure.;;Description :;;The remote host appears to be running a BasiliX version 1.1.0 or lower. Such versions allow retrieval of arbitrary;files that are accessible to the web server user when sending a message since they accept a list of attachment;names from the client yet do not verify that the attachments were in fact uploaded.;;Further, since these versions do not sanitize input to the 'login.php3' script, it's possible for an attacker to;establish a session on the target without otherwise having access there by authenticating against an IMAP server;of his or her choosing.
Description:Summary:
The remote web server contains a PHP script that is prone to information
disclosure.

Description :

The remote host appears to be running a BasiliX version 1.1.0 or lower. Such versions allow retrieval of arbitrary
files that are accessible to the web server user when sending a message since they accept a list of attachment
names from the client yet do not verify that the attachments were in fact uploaded.

Further, since these versions do not sanitize input to the 'login.php3' script, it's possible for an attacker to
establish a session on the target without otherwise having access there by authenticating against an IMAP server
of his or her choosing.

Solution:
Upgrade to BasiliX version 1.1.1 or later.

CVSS Score:
3.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1710
BugTraq ID: 5062
http://www.securityfocus.com/bid/5062
Bugtraq: 20020618 BasiliX multiple vulnerabilities (Google Search)
http://archive.cert.uni-stuttgart.de/archive/bugtraq/2002/06/msg00247.html
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0117.html
XForce ISS Database: basilix-webmail-attach-files(9386)
https://exchange.xforce.ibmcloud.com/vulnerabilities/9386
CopyrightCopyright (C) 2004 George A. Theall

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.