5
CVSSv2

CVE-2008-0333

Published: 17/01/2008 Updated: 02/11/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote malicious users to read arbitrary files via a .. (dot dot) in the temp_filename parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

afterlogic mailbee webmail pro 4.1

Exploits

homepage: wwwafterlogiccom example: wwwxxxcom/webmail-pro-net/download_view_attachmentaspx?temp_filename=//////////////////bootini -=MoB=- # milw0rmcom [2008-01-16] ...