7.2
CVSSv2

CVE-2002-1385

Published: 26/12/2002 Updated: 10/10/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

openwebmail_init in Open WebMail 1.81 and previous versions allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed.

Vulnerable Product Search on Vulmon Subscribe to Product

open webmail open webmail 1.81

open webmail open webmail 1.7

open webmail open webmail 1.71

open webmail open webmail 1.8