Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EMUMail Arbitrary File Reading Vulnerability

Emumail is a web mail package available from Emumail, Inc. It is designed for use on Linux, Unix, and Windows systems.

It may be possible for a remote user to gain access to some files through email. By supplying the full path to a file as an argument to the type= function of emumail.cgi, a user may be able to see the contents of the specified file. The request must end with a null character (%00).







 

Privacy Statement
Copyright 2009, SecurityFocus