mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email…
Info
Summary
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html Exploit
- http://www.securityfocus.com/bid/1807 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5358
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html Exploit
- http://www.securityfocus.com/bid/1807 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5358
Timeline
- nvd_ingest NVD