SqWebMail Session Hijacking Vulnerability...

- AV AC AU C I A
发布: 2003-11-17
修订: 2025-04-13

SqWebMail is prone to a vulnerability that may allow remote attackers to hijack webmail sessions. This vulnerability occurs if the victim user follows a malicious link provided by an attacker via an e-mail that is viewed from the webmail system. This will permit an attacker to gain unauthorized access to the user's session ID, which may be then used to hijack the user's session, if it hasn't timed out. SqWebMail is included in the Courier mail server, but is also available as a stand-alone CGI application.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息