85
Mercur Mailserver 3.2 directory traversal
SMTP
2004/03/23
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.2
Corrected the plugin structure and added the accuracy values in 1.2
tcp
25
open|sleep|close|pattern_exists 220 *MERCUR SMTP-Server (3.2*
80
This plugin was written with the ATK Attack Editor.
Mercur SMTP-Server 3.2
Mercur SMTP-Server 3.3 and newer
Evasion
The Mercur Mailserver is a small Mail Transfer Agent (MTA). There were a directory traversal vulnerability posted. Any email message in a known mailbox of a known user can be read by remote users through path definitions as like /../../directory. To exploit this vulnerability is a successfull mailserver login required.
This issue seems to be resolved in newer versions of Mercur Mailserver. Please update to the latest version.
1 hour
Yes
Yes
Yes
High
7
7
8
7
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch