Re: [Full-Disclosure] The Macallan mail solution 4.0.6.8 (Build 786) contains several vulnerabilities

2005-01-04 Thread Alex V. Lukyanenko
Hello CIRT, DO you people think you digitally sign your correspondence by attaching a public key block to the end? EEEK! I prefer to stay quiet about using an insecure-unless-proven-otherwise type of MUA. Friday, December 31, 2004, 2:29:29 PM, you wrote: ... CA> X-Mailer: Microsoft Outlook, Build

[Full-Disclosure] The Macallan mail solution 4.0.6.8 (Build 786) contains several vulnerabilities

2005-01-01 Thread CIRT Advisory
The Macallan Mail Solution are vulnerable to the problems shown below: "Macallan Mail Solution Web Interface Authentication Bypass" similar to vulnerability reported earlier by Secunia http://secunia.com/advisories/10861/ Denial of Service when requesting an overly long URL starting with