J-Security Center

Title: Floosietek FTGate Mail Server Path Disclosure Vulnerability

Severity: MODERATE

Description:

FTGate is a family of email server software supporting such features as webmail, anti-virus and even dial up networking. The software is commercially available for the Microsoft Windows platform.

It has been reported that FTGate it prone to a server path disclosure vulnerability. This issue is due to an ill conceived error message that includes the server path.

The problem presents itself when an error occurs when the 'inbox/message.fts' script is requested. By triggering an error in the script, an error message will be displayed that presents the server installation path to the user.

These issues may be leveraged to gain sensitive information about the affected system potentially aiding an attacker in mounting further attacks.

Affected Products:

  • Floosietek FTGateOffice 1.2.0
  • Floosietek FTGatePro 1.2.0
  • Floosietek FTGatePro 1.2.0(1331)

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.