Rockliffe`s MailSite Express AttachPath obtain information

mailsiteexpress-attachpath-obtain-info (22908) The risk level is classified as MediumMedium Risk

Description:

Rockliffe's MailSite Express could allow a remote attacker to obtain sensitive information. A remote attacker could include a statement in an email containing a specially-crafted AttachPath variable to include an arbitrary attachment file in an email.


Consequences:

Obtain Information

Remedy:

Upgrade to the latest version of MailSite (6.1.22 or later). available from the MailSite Web site. See References.

References:

  • Full-Disclosure Mailing List, Fri Oct 28 2005 - 00:32:25 CDT: Multiple vulnerabilities within RockLiffe MailSite Express WebMail.
  • Rockliffe - Rock Solid Internet Software: Webmail Server: MailSite - Rockliffe.
  • BID-15230: Rockliffe MailSite Express Arbitrary Script File Upload Vulnerability
  • BID-15231: Rockliffe MailSite Express Information Disclosure Vulnerability
  • CVE-2005-3431: Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a mail message under composition.
  • SA17240: MailSite Express Attachment Upload and Script Insertion
  • SECTRACK ID: 1015117: RockLiffe MailSite Express WebMail Discloses WebMail Files to Remote Users and Permits Cross-Site Scripting Attacks

Platforms Affected:

  • Rockliffe MailSite Express prior to 6.1.22

Reported:

Oct 28, 2005

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page