6.4
CVSSv2

CVE-2002-2399

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cascadesoft w3mail 1.0.6

Exploits

source: wwwsecurityfocuscom/bid/6170/info Versions of W3Mail 106 and greater are susceptible to a file disclosure vulnerability To view attachments, the script "viewAttachmentcgi" accepts the parameter "file" The value of this parameter is passed to the open() function as the filename argument without being sanitized Attackers may c ...