5
CVSSv2

CVE-2002-1581

Published: 06/12/2004 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 up to and including 2.3.31 allows remote malicious users to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mailreader.com mailreader.com 2.3.24

mailreader.com mailreader.com 2.3.25

mailreader.com mailreader.com 2.3.26

mailreader.com mailreader.com 2.3.27

mailreader.com mailreader.com 2.3.22

mailreader.com mailreader.com 2.3.23

mailreader.com mailreader.com 2.3.30

mailreader.com mailreader.com 2.3.31

mailreader.com mailreader.com 2.3.20

mailreader.com mailreader.com 2.3.21

mailreader.com mailreader.com 2.3.28

mailreader.com mailreader.com 2.3.29

debian debian linux 3.0

Vendor Advisories

A directory traversal vulnerability was discovered in mailreader whereby remote attackers could view arbitrary files with the privileges of the nph-mrcgi process (by default, www-data) via relative paths and a null byte in the configLanguage parameter For the current stable distribution (woody), this problem has been fixed in version 2329-5wood ...

Exploits

source: wwwsecurityfocuscom/bid/6055/info A vulnerability exists in Mailreadercom which may enable remote attackers to disclose the contents of arbitrary webserver readable files An attacker may exploit this issue by submitting a malicious web request containing dot-dot-slash (/) directory traversal sequences The request must be for ...