PT-2009-2743 · Squirrelmail+1 · Squirrelmail+1

·

CVE-2009-0030

·

Publicado

2009-01-19

·

Atualizado

2023-02-13

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SquirrelMail version 1.4.8
Description The issue allows remote authenticated users to access other users' folder lists and configuration data under certain circumstances by using the standard webmail.php interface. This occurs because a Red Hat patch for SquirrelMail sets the same SQMSESSID cookie value for all sessions.
Recommendations For SquirrelMail version 1.4.8, consider disabling the use of the SQMSESSID cookie until a proper fix is applied to prevent unauthorized access to user data. Restrict access to the webmail.php interface to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0030
RHSA-2009:0057
RHSA-2009_0057

Produtos afetados

Red Hat
Squirrelmail