vendor:
i-dreams Mailer
by:
Pouya_Server
7.5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: i-dreams Mailer
Affected Version From: 1.2 Final
Affected Version To: 1.2 Final
Patch Exists: YES
Related CWE: N/A
CPE: a:pouya_server:i-dreams_mailer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
i-dreams Mailer 1.2 Final
This vulnerability allows remote attackers to include and execute arbitrary local or remote files via a URL in the 'admin.dat' parameter in the 'cgi-bin/budmail/data/' directory.
Mitigation:
The vendor has released a patch to address this vulnerability.