Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/297428 | Exploit Patch Vendor Advisory |
http://www.debian.org/security/2004/dsa-534 | Patch Vendor Advisory |
http://www.iss.net/security_center/static/10490.php | Patch Vendor Advisory |
http://www.securityfocus.com/bid/6055 | Exploit Patch Vendor Advisory |
http://mailreader.com/download/ChangeLog |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2004-12-05 21:00
Updated : 2011-03-07 18:10
NVD link : CVE-2002-1581
Mitre link : CVE-2002-1581
JSON object : View
CWE
Products Affected
debian
- debian_linux
mailreader.com
- mailreader.com