Wubi Posted July 24, 2012 Report Posted July 24, 2012 (edited) Atmail WebAdmin and Webmail Control Panel SQL Root Password Disclosure[table=width: 500, class: grid][tr] [td]EDB-ID: 20037[/td] [td]CVE: N/A [/td] [td]OSVDB-ID: N/A[/td][/tr][tr] [td]Author: Ciph3r[/td] [td]Published: 2012-07-23[/td] [td]Verified: [/td][/tr][tr] [td]Exploit Code: [/td] [td]Vulnerable App: N/A[/td] [td][/td][/tr][/table]####################################################################################### Vuln Title: Atmail WebAdmin and webmail Control Panel Remote Access SQL Root password Vulnerability## Author: FaryadR (a.k.a Ciph3r)# tested on : Atmail Email Server 6.20.8# Twitter : https://twitter.com/faryadR# Mail : Ciph3r.secure@gmail.com# Website : http://0c0c0c0c.com# Vendor : http://atmail.com# Powered by Atmail 6.20.8 - WebAdmin Control Panel ####################################################################################### [+]Vulnerability : you can Access All Atmail Webadmin Mail server Configuration and SQL Root Password [+]Poc : Go to webmail and config Directory and type dbconfig.ini for Access all SQL Configuration [+]Demo for Test Vuln : [+]Atmail 6.20.8http://server/config/dbconfig.ini Edited July 24, 2012 by Wubi Quote