Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ipswitch Imail用户邮箱泄露漏洞
Vulnerability Description
Ipswitch IMail 7.04及其早期版本在URL中存储用户的session ID,远程攻击者通过获取URL拦截sessions,比如借助导致发送Referrer到攻击者控制下URL的HTML电子邮件。
CVSS Information
N/A
Vulnerability Type
N/A