Vulnerability Name: | CVE-2001-1281 (CCN-7273) | ||||||||
Assigned: | 2001-10-11 | ||||||||
Published: | 2001-10-11 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: BUGTRAQ Type: Vendor Advisory 20011011 Vulnerabilities in Ipswitch IMail Server 7.04 Source: CCN Type: BugTraq Mailing List, Thu Oct 11 2001 - 15:01:26 CDT Vulnerabilities in Ipswitch IMail Server 7.04 Source: CCN Type: BugTraq Mailing List, Thu Oct 11 2001 - 16:32:12 CDT Re: Vulnerabilities in Ipswitch IMail Server 7.04 Source: MITRE Type: CNA CVE-2001-1281 Source: CCN Type: ntsecurity.nu Security Advisory #16 Vulnerabilities in Ipswitch IMail Server 7.04 Source: MISC Type: UNKNOWN http://www.ipswitch.com/Support/IMail/news.html Source: CCN Type: Ipswitch Web site IMail Server Support Center > Patches & Upgrades Source: CCN Type: OSVDB ID: 10849 Ipswitch IMail Web Messaging Server Arbitrary User Information Modification Source: BID Type: UNKNOWN 3429 Source: CCN Type: BID-3429 Ipswitch IMail Server User Modification Vulnerability Source: XF Type: UNKNOWN imail-change-user-info(7273) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |