OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: tfmtfm.org
Date: Wed Jul 03 2002 - 04:28:06 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Hi, it's not working on 3.5.9 (not a beta release) :
    Verified on Linux and Solaris.

    TfM

    ----- Original Message -----
    From: <c0rrect0rhushmail.com>
    To: <bugtraqsecurityfocus.com>
    Sent: Tuesday, July 02, 2002 7:56 AM
    Subject: CommuniGate Pro directory listings

    > Problem:
    > An anonymous user can see the listing of the current and parent directory
    of CommuniGatePro WebUser directory.
    > Vulnerable:
    > All current versions of CommuniGatePro <= 4.0b4
    > Details:
    > You can get the listing of directory by accessing the CommuiGatePro
    webmail for example http://host.com/. or http://host.com/..