Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MDaemon WorldClient邮件客户端漏洞
Vulnerability Description
MDaemon 2.8版本WorldClient邮件客户端在用户点击URL时包含提交者HTTP字段请求会话ID。访问web站点可以利用该漏洞劫持会话ID并读取用户邮件。
CVSS Information
N/A
Vulnerability Type
N/A