Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
Info
Summary
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html Vendor Advisory
- http://www.securityfocus.com/bid/1738 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5326
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html Vendor Advisory
- http://www.securityfocus.com/bid/1738 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5326
Timeline
- nvd_ingest NVD