3290Third-party advisory
http://securityreason.com/securityalert/3290 CVE-2003-1481
CommuniGate Pro Webmail 4.0.6 - Session Hijacking
Record summary
CVE-2003-1481 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.
Description
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCommuniGate Pro Webmail 4.0.6 - Session HijackingExploitDB exploitby Yaroslav PolyakovNot analyzed1 file
References
520030504 CommuniGatePro 4.0.6 [EXPLOIT]mailing list
http://www.securityfocus.com/archive/1/320438 7501vdb entry
http://www.securityfocus.com/bid/7501 communigate-pro-session-hijacking(11932)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/11932 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-1481