what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

eGroupWare_infoleak.txt

eGroupWare_infoleak.txt
Posted Apr 18, 2005
Authored by Gerald Quakenbush | Site mastermindsecuritygroup.com

eGroupWare contains a bug where mail attachments could be sent to the wrong recipient by mistake, due to eGroupWare caching attachments after a user decides to cancel a message.

tags | exploit
SHA-256 | 749dead5a3d9e61cb8aeed7fe8e36c08cea5e025ab202d7a3da558e4ee54b64c

eGroupWare_infoleak.txt

Change Mirror Download
MasterMind Security Group, Inc.
Security Brief

Date: April 7, 2005
Contact: Gerald Quakenbush <geraldq AT mastermindsecuritygroup.com>
Severity: Moderate to Serious
Product: Confirmed in eGroupWare 1.001 and 1.006

Synopsis
========
The eGroupWare open-source software (www.egroupware.org) has a flaw that could
expose confidential information.

The eGroupWare suite provides many applications via a web interface. One such
application is for email. A flaw in this application could result in the
unwitting disclosure of files.

If a user composes a message and attaches a file, then decides not to send the
message, the attachment will get sent to the next person the user emails.
There is no indication in the message window that the file from the previous
message is still attached, unless the user clicks on the button to attach a
file to the second message.

Mitigation
==========
Until a patch is issued to resolve the problem, be aware of this issue. If you
attach a file to a message and then decide not to send it, logout of
eGroupWare then log back on before sending any new messages.

Walk Through
============

Login to eGroupWare using an account that has email configured.

Step 1. After logging in, select the email icon on the tool bar.

Step 2. Click the Compose button to create a new message and attach a file. Do
NOT click Send.

Step 3. Without sending the message, return to the inbox. You can click the
inbox link on the left of the email icon on the toolbar.

Step 4. You are now back at the main inbox screen. Click on the Compose link
again.

Step 5. Enter an email address (a personal account or one of a trusted friend,
preferably), a subject and brief message if you like and click Send.

Step 6. Now check the email for the account you sent the message to above. The
attachment from the canceled message in step 2 will be attached.

-Quake

--
------------------------------------
Gerald Quakenbush, CISSP, NSA-IAM
MasterMind Security Group, Inc.
888.295.6012 x701
http://www.mastermindsecuritygroup.com


Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close