IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.
Info
Summary
IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://www.securityfocus.com/archive/1/82088 Patch
- http://www.securityfocus.com/bid/1679 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5227
- http://www.securityfocus.com/archive/1/82088 Patch
- http://www.securityfocus.com/bid/1679 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5227
Timeline
- nvd_ingest NVD