5
CVSSv2

CVE-2002-1527

Published: 02/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

emumail.cgi in EMU Webmail 5.0 allows remote malicious users to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message.

Vulnerable Product Search on Vulmon Subscribe to Product

emumail emu webmail 5.0

Exploits

source: wwwsecurityfocuscom/bid/5823/info Emumail is an open source web mail application It is available for the Unix, Linux, and Microsoft Windows operating systems Under some conditions, Emumail may reveal sensitive configuration information When unexpected characters are inserted into some fields in web mail forms, the form generat ...