Re: [vchkpw] Fwd: PCL-0002: Session Hijacking in "Sqwebmail"

2003-11-17 Thread Rainer Duffner
On Mon, 17 Nov 2003 11:14:24 -0800 Anthony Baratta <[EMAIL PROTECTED]> wrote: > For those that use SqWebMail...this came across BugTraq. > > >Date: Tue, 18 Nov 2003 02:18:04 +0100 (CET) > >From: Vincenzo Ciaglia <[EMAIL PROTECTED]> > >To: [EMAIL PROTECTED] > >Subject: PCL-0002: Session Hijacking

Re: [vchkpw] Fwd: PCL-0002: Session Hijacking in "Sqwebmail"

2003-11-17 Thread Paul Theodoropoulos
i realize the author isn't a native english speaker, but this is ridiculous, to wit: Package : Sqwebmail Vendor : Inter7 Vulnerability : access to private account without login, session hijacking Problem-Type : remote risk : low ^ "risk: lo

Re: [vchkpw] Fwd: PCL-0002: Session Hijacking in "Sqwebmail"

2003-11-17 Thread X-Istence
Anthony Baratta wrote: For those that use SqWebMail...this came across BugTraq. * What could make a attacker? * Read, write and fake your e-mail. Could send , from you email address, a mail to your ISP and ask it User e PASS of your website. The c

[vchkpw] Fwd: PCL-0002: Session Hijacking in "Sqwebmail"

2003-11-17 Thread Anthony Baratta
For those that use SqWebMail...this came across BugTraq. Date: Tue, 18 Nov 2003 02:18:04 +0100 (CET) From: Vincenzo Ciaglia <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: PCL-0002: Session Hijacking in "Sqwebmail" --- PUCCIOLAB.ORG - ADVISORIES