Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2001-1286

Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2001-1286
  • Ipswitch » Imail » Version: 6.0.2
    cpe:2.3:a:ipswitch:imail:6.0.2
  • Ipswitch » Imail » Version: 6.0.6
    cpe:2.3:a:ipswitch:imail:6.0.6
  • Ipswitch » Imail » Version: 7.0.4
    cpe:2.3:a:ipswitch:imail:7.0.4


Contact Us

Shodan ® - All rights reserved