Record summary

CVE-2003-1481 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.

Description

CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCommuniGate Pro Webmail 4.0.6 - Session HijackingExploitDB exploitby Yaroslav PolyakovNot analyzed1 file
ExploitDB

PoC details

References

5