9
CVSSv2

CVE-2008-4932

Published: 05/11/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote malicious users to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.

Vulnerable Product Search on Vulmon Subscribe to Product

comingchina u-mail webmail server 4.91

Exploits

U-Mail Webmail Arbitrary File Write Vulnerability ================================================== Vulnerable: U-Mail 491 Vendors: wwwcomingchinacom Category: Input Validation Error Impact: An attacker can write arbitrary data to new files Author: Shennan Wang Date: 2008-10-30 Web: hibaiducom/nansec Details: ========= ...