The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0911, does not remove the session ID in a Referer URL, which allows remote attackers to hijack web sessions via vectors such as an email with an embedded URL.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN85821104/index.html | third party advisory |
http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000076.html | third party advisory |
http://www.transware.co.jp/support_am/security/vulnerability3.html | vendor advisory |
http://secunia.com/advisories/37602 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/54751 | vdb entry |