积极预防 及时发现
快速响应 力保恢复
Mdaemon 2.8中的WorldClient电子邮件客户在用户点击一个URL时在HTTP请求的r...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000716 CVE编号:CVE-2000-0716 安全级别:中 漏洞中文描述: Mdaemon 2.8中的WorldClient电子邮件客户在用户点击一个URL时在HTTP请求的referer域中包含会话ID,这导致被访问的站点攻击会话ID以及读取用户的电子邮件。 漏洞英文描述: WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijcak the session ID and read the user's email. 漏洞参考: 系统类型:其他 漏洞类型:其他