Reported March 12, 2002, by Obscure.

VERSION AFFECTED

  • Ipswitch IMail Server version 7.05 and earlier

DESCRIPTION
When a user logs on to his or her account through the IMail Server Web interface, the application uses a unique URL to maintain the session authentication. By sending an HTML email message that references an image on another server, an attacker can easily obtain the unique URL via the referrer field in the HTTP header.


VENDOR RESPONSE

The vendor, Ipswitch, has released version 7.06, which resolves this issue.


CREDIT
Discovered by Obscure.