5
CVSSv2

CVE-2000-0977

Published: 19/12/2000 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

mailfile.cgi CGI program in MailFile 1.10 allows remote malicious users to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

oatmeal studios mail file 1.10

Exploits

source: wwwsecurityfocuscom/bid/1807/info OatMeal studios' Mail-File is a cgi application that allows for sending of certain files to user-specified email addresses via a web interface A vulnerability exists in this script that can be used to send the contents of <i>any</i> readable user-specified files to an email address W ...