The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
http://forums.wizard.ca/viewtopic.php?f=17&t=236760 | vendor advisory |
https://www.vulnerability-lab.com/get_content.php?id=2113 | third party advisory exploit |