CVE-2003-1481

CommuniGate Pro 3.1-4.0.6 - Session Hijacking via Referer Field Exposure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1481. PoCs published by Yaroslav Polyakov.

AI-analyzed exploit summary This exploit leverages session hijacking in CommuniGatePro 4.0.6 by extracting a session ID from the HTTP_REFERER header and using it to fetch emails from the victim's mailbox. It disguises itself as a 1x1 pixel GIF to trick the victim into executing the attack.

Description

CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Yaroslav Polyakov · perlremotelinux
https://www.exploit-db.com/exploits/27

This exploit leverages session hijacking in CommuniGatePro 4.0.6 by extracting a session ID from the HTTP_REFERER header and using it to fetch emails from the victim's mailbox. It disguises itself as a 1x1 pixel GIF to trick the victim into executing the attack.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: CommuniGatePro 4.0.6
No auth needed
Prerequisites: Victim must visit a page with the malicious image link · Victim must have an active session in CommuniGatePro webmail · Attacker must be able to intercept or infer the victim's session ID via HTTP_REFERER
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/320438
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3290
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/7501
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11932

Scores

EPSS 0.0184
EPSS Percentile 76.2%

Details

CWE
CWE-200
Status published
Products (14)
stalker/communigate_pro 3.1
stalker/communigate_pro 3.2.4
stalker/communigate_pro 3.2_b5
stalker/communigate_pro 3.2_b7
stalker/communigate_pro 3.3.2
stalker/communigate_pro 3.3_b1
stalker/communigate_pro 3.3_b2
stalker/communigate_pro 3.4_b3
stalker/communigate_pro 4.0.1
stalker/communigate_pro 4.0.2
... and 4 more
Published Dec 31, 2003
Tracked Since Feb 18, 2026