Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name.
Link | Tags |
---|---|
http://securitytracker.com/id?1009030 | vdb entry |
http://www.osvdb.org/3926 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15194 | vdb entry |
http://secunia.com/advisories/10861 | third party advisory |
http://www.securityfocus.com/bid/9646 | vdb entry exploit |
https://testzone.secunia.com/advisories/10861 |