5
CVSSv2

CVE-2007-3702

Published: 11/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.

Vulnerable Product Search on Vulmon Subscribe to Product

mail machine mail machine 3.987

mail machine mail machine 3.988

mail machine mail machine 3.989

mail machine mail machine 3.980

mail machine mail machine 3.985

Exploits

#!/usr/bin/perl -w #__________________________________________________________________________ # [*] Mail Machine Local File Include Exploit # [*] Vuln v3980, v3985, v3987, v3988 and v3989 # __________________________________________________________________________ # [!] Application homepage : wwwmikesworldnet/mailmachineshtml ...