Open WebMail 2.30 and previous versions, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote malicious users to create arbitrary directories.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
open webmail open webmail 1.7 |
||
open webmail open webmail 1.71 |
||
open webmail open webmail 1.90 |
||
open webmail open webmail 2.30 |
||
open webmail open webmail 1.8 |
||
open webmail open webmail 1.81 |