Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zarafa WebAccess和WebApp 本地信息泄露漏洞
Vulnerability Description
Zarafa是荷兰Zarafa公司的一套商业性协作式软件解决方案,该方案提供了Email和Webmail服务、地址簿和日历等功能。WebAccess和WebApp都是其中的应用软件。 Zarafa 7.1.10之前版本中的WebApp 1.6之前版本和WebAccess中存在安全漏洞,该漏洞源于程序使用明文存储凭证。本地Apache用户可通过读取PHP会话文件利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A