Synopsis
The remote web server is vulnerable to a SQL injection attack.
Description
The remote host is running the iXmail webmail interface.
There is a flaw in this interface that allows an attacker to log in as any user by using a SQL injection flaw in the code of index.php.
An attacker may use this flaw to gain unauthorized access on this host, or to gain the control of the remote database.
Solution
Upgrade to iXMail 0.4.
Plugin Details
File Name: ixmail_sql_injection.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 8047