5
CVSSv2

CVE-2002-0410

Published: 26/07/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

send_message.php in AeroMail prior to 1.45 allows remote malicious users to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

Vulnerable Product Search on Vulmon Subscribe to Product

aeromail aeromail 1.02

aeromail aeromail 1.10

aeromail aeromail 1.20

aeromail aeromail 1.30

aeromail aeromail 1.26

aeromail aeromail 1.40