Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FormHandler.cgi Reply Attachment Vulnerability

Any file that the FormHandler.cgi has read access to (the cgi is typically run as user 'nobody' on Unix systems) can be specified as an attachment in a reply email. This could allow an attacker to gain access to sensitive files such as /etc/passwd simply by modifying the form document.







 

Privacy Statement
Copyright 2009, SecurityFocus