CVE-2001-1286: High severity Ipswitch IMail vulnerability
Published Oct 12, 2001
·Updated
Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.
Affected Software
3 affected components
Ipswitch IMail=6.0.6
Ipswitch IMail=6.0.2
Ipswitch IMail=7.0.4
Remediation
Patch Available
Event History
Oct 12, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1286?
CVE-2001-1286 has a medium severity rating due to the potential for session hijacking.
2
How do I fix CVE-2001-1286?
To fix CVE-2001-1286, it is recommended to upgrade to Ipswitch IMail versions later than 7.0.4.
3
Who is affected by CVE-2001-1286?
CVE-2001-1286 affects Ipswitch IMail versions 6.0.2, 6.0.6, and 7.0.4 and earlier.
4
What type of vulnerability is CVE-2001-1286?
CVE-2001-1286 is a session management vulnerability that allows session hijacking.
5
Can CVE-2001-1286 be exploited remotely?
Yes, CVE-2001-1286 can be exploited remotely if an attacker can obtain the session ID through crafted URLs.