CVE

Id
30327  
CVE No.
CVE-2008-0210  
Status
Candidate  
Description
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.  
Phase
Assigned (20080109)  
Votes
None (candidate not yet proposed)  
Comments