[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Internal Information Disclosure in McAfee Email Gateway (formerly IronMail)
# Published : 2010-04-06
# Author : Nahuel Grisolia
# Previous Title : Local Privilege Escalation in McAfee Email Gateway (formerly IronMail)
# Next Title : PHP 6.0 Dev str_transliterate() 0Day Buffer Overflow Exploit


Advisory Name: Internal Information Disclosure in McAfee Email Gateway (formerly IronMail)
Vulnerability Class: Information Disclosure
Release Date: Tue Apr 6, 2010
Affected Applications: Secure Mail (Ironmail) ver.6.7.1
Affected Platforms: FreeBSD 6.2 / Apache-Coyote 1.1
Local / Remote: Local
Severity: Low ¨C CVSS: 1.7 (AV:L/AC:L/Au:S/C:P/I:N/A:N)
Researcher: Nahuel Grisol¨ªa

Vendor Status: Official Patch Released. Install McAfee Email Gateway 6.7.2 Hotfix 2.
Reference to Vulnerability Disclosure Policy: http://www.cybsec.com/vulnerability_policy.pdf

Vulnerability Description:
Some files that allow to obtain usernames and other internal information can be read by any user inside
the CLI.

http://www.exploit-db.com/sploits/cybsec_advisory_2010_0403.pdf