CVE-2012-1920: Infoleak
Published Mar 27, 2012
·Updated
@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
Affected Software
1 affected component
Atmail AtMail Open<=1.04
Event History
Mar 27, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1920?
CVE-2012-1920 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-1920?
To fix CVE-2012-1920, upgrade to AtMail Open-Source version 1.05 or later.
3
What information can be leaked due to CVE-2012-1920?
CVE-2012-1920 allows remote attackers to obtain sensitive configuration information from the server.
4
Which versions of AtMail are affected by CVE-2012-1920?
AtMail Open-Source versions up to and including 1.04 are affected by CVE-2012-1920.
5
Can CVE-2012-1920 be exploited without authentication?
Yes, CVE-2012-1920 can be exploited by remote attackers without any authentication requirements.