7.2
CVSSv2

CVE-2002-1741

Published: 31/12/2002 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and previous versions allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

alt-n worldclient 5.0.1

alt-n worldclient 5.0.2

alt-n worldclient 5.0.5

alt-n worldclient 5.0

alt-n worldclient 5.0.3

alt-n worldclient 5.0.4

Exploits

source: wwwsecurityfocuscom/bid/4687/info WorldClient is a web interface packaged with MDaemon, an email server for Microsoft Windows An input validation vulnerability exists in WorldClient that allows for an attacker to delete an arbitrary file on the webserver that it resides on The vulnerability is due to a lack of input validation ...