85 Mercur Mailserver 3.2 directory traversal SMTP 2004/03/23 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.2 Corrected the plugin structure and added the accuracy values in 1.2 tcp 25 open|sleep|close|pattern_exists 220 *MERCUR SMTP-Server (3.2* 80 This plugin was written with the ATK Attack Editor. Mercur SMTP-Server 3.2 Mercur SMTP-Server 3.3 and newer Evasion The Mercur Mailserver is a small Mail Transfer Agent (MTA). There were a directory traversal vulnerability posted. Any email message in a known mailbox of a known user can be read by remote users through path definitions as like /../../directory. To exploit this vulnerability is a successfull mailserver login required. This issue seems to be resolved in newer versions of Mercur Mailserver. Please update to the latest version. 1 hour Yes Yes Yes High 7 7 8 7 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch