Sun JavaMail 1.3 - API MimeMessage Infromation Disclosure

EDB-ID:

25685

CVE:

N/A




Platform:

JSP

Date:

2005-05-19


source: https://www.securityfocus.com/bid/13683/info

The MimeMessage method in the Sun JavaMail API does not perform sufficient validation on message number values that are passed to the method during requests. An attacker that can successfully authenticate to an email server implementation that is written using the Sun JavaMail API, may exploit this issue to make requests for arbitrary email messages that are stored on the server. 

http://www.example.com/ReadMessage.jsp?msgno=10001
http://www.example.com/ReadMessage.jsp?msgno=10002