CVE-2001-1285: Medium severity Ipswitch IMail vulnerability
Published Oct 12, 2001
·Updated
Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter.
Affected Software
3 affected components
Ipswitch IMail=6.0.6
Ipswitch IMail=6.0.2
Ipswitch IMail=7.0.4
Event History
Oct 12, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1285?
CVE-2001-1285 is considered a high severity vulnerability due to its ability to allow unauthorized access to user mailboxes.
2
How do I fix CVE-2001-1285?
To fix CVE-2001-1285, upgrade to the latest version of Ipswitch IMail that does not contain this vulnerability.
3
What software versions are affected by CVE-2001-1285?
CVE-2001-1285 affects Ipswitch IMail versions 6.0.2, 6.0.6, and 7.0.4 and earlier.
4
What kind of attack exploits CVE-2001-1285?
CVE-2001-1285 can be exploited through directory traversal attacks using the mbx parameter to access restricted files.
5
Can CVE-2001-1285 lead to data breaches?
Yes, CVE-2001-1285 can lead to data breaches by allowing attackers to access sensitive mailbox information of other users.