First published: Wed Dec 31 2003(Updated: )
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stalker CommuniGate Pro | =3.2_b5 | |
Stalker CommuniGate Pro | =4.0_b3 | |
Stalker CommuniGate Pro | =3.3_b2 | |
Stalker CommuniGate Pro | =3.1 | |
Stalker CommuniGate Pro | =3.3_b1 | |
Stalker CommuniGate Pro | =4.0.1 | |
Stalker CommuniGate Pro | =4.0.6 | |
Stalker CommuniGate Pro | =4.0_b2 | |
Stalker CommuniGate Pro | =3.4_b3 | |
Stalker CommuniGate Pro | =3.2.4 | |
Stalker CommuniGate Pro | =4.0.2 | |
Stalker CommuniGate Pro | =3.2_b7 | |
Stalker CommuniGate Pro | =4.0.3 | |
Stalker CommuniGate Pro | =3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.