CVE-2000-0780: Medium severity Ipswitch IMail vulnerability
Published Oct 13, 2000
·Updated
The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.
Affected Software
6 affected components
Ipswitch IMail=5.0
Ipswitch IMail=6.0
Ipswitch IMail=6.1
Ipswitch IMail=6.2
Ipswitch IMail=6.3
Ipswitch IMail=6.4
Event History
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0780?
CVE-2000-0780 has been classified as a medium severity vulnerability due to its potential to allow unauthorized access to server files.
2
How do I fix CVE-2000-0780?
To fix CVE-2000-0780, upgrade to IPSWITCH IMail version 6.5 or above, which addresses this vulnerability.
3
What impact does CVE-2000-0780 have on affected systems?
CVE-2000-0780 allows remote attackers to read and delete arbitrary files on the server, which can lead to data loss or breach.
4
Which versions of IPSWITCH IMail are affected by CVE-2000-0780?
IPSWITCH IMail versions 5.0 to 6.4 are affected by CVE-2000-0780.
5
Is there a workaround for CVE-2000-0780 until I can upgrade?
Disabling remote file access and implementing strict file permissions can serve as a temporary workaround for CVE-2000-0780.