Re: Remote Execution of Commands in Omail Webmail 0.98.4 and earlier

From: Olivier M. (qmail_at_orion.8304.ch)
Date: 08/21/03

  • Next message: Balwinder Singh: "Re: Need help. Proof of concept 100% security."
    Date: Thu, 21 Aug 2003 11:24:30 +0200
    To: Phillip Whelan <pwhelan@bunkerchile.net>, bugtraq@securityfocus.com
    
    

    On Tue, Aug 19, 2003 at 07:15:32PM -0000, Phillip Whelan wrote:
    > Product: Omail Webmail
    > The flaw occurs in the function checklogin();

    thx, version 0.98.5 released today, including your bugfix:
    http://prdownloads.sourceforge.net/omail/omail-webmail-0.98.5.tar.gz

    > The author was contacted two weeks ago, but did not
    > respond.

    summertime -> ever heard of holidays... ? :)

    regards,
    Olivier

    -- 
    _________________________________________________________________
     Olivier Mueller - om@8304.ch - PGPkeyID: 0E84D2EA - Switzerland
    qmail projects: http://omail.omnis.ch  -  http://webmail.omnis.ch
    

  • Next message: Balwinder Singh: "Re: Need help. Proof of concept 100% security."

    Relevant Pages

    • Re: windows update doesnt work at all, neither does auto updates
      ... > thx 4 all ur help........auto update just popped up with updates!! ... >> You should be keying in regsvr and not regsur (I suspect that this is ... >> Regards, ... >> Patti MacLeod ...
      (microsoft.public.windowsupdate)
    • Re: How to kill Excel Instance
      ... Thx a lot ... Regards, ... Rudy ... > Tom Ogilvy ...
      (microsoft.public.excel.programming)
    • Re: How to get the ADO Connection s RecordAffected Value
      ... Thx for your help ~ ... >> I am trying to execute multiple SQL Statement in one Connection.Execute ... >> Dim sSQL as String ... >> Regards, ...
      (microsoft.public.vb.database.ado)
    • RE: Addin, Funtion
      ... > now what I wanna do it's to have this formula into a funtion in a add in ... so I can use it on diferent workbooks that I used daily so I can save ... thx. ... >> Regards, ...
      (microsoft.public.excel.programming)
    • Re: Thread synchronization problem
      ... Thx. ... Best regards ... >> be actualy terminated few milliseconds after. ... > complex for such simple sync scenario ...
      (microsoft.public.dotnet.languages.csharp)