vendor:
Aconon Mail
by:
Unknown
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Aconon Mail
Affected Version From: All known versions, tested against 2007 Enterprise SQL 11.7.0 and 2004 Enterprise SQL 11.5.1
Affected Version To: Unknown
Patch Exists: No
Related CWE: Unknown
CPE: aconon-mail
Platforms Tested: Win32, Linux, Solaris
2008
Directory Traversal Vulnerability in Aconon Mail
Aconon Mail is a commercial newsletter software that allows users to access archived emails through a web browser. The template used for processing these emails can be overwritten by any user, allowing for directory traversal attacks. An attacker can modify the 'template' form parameter in the HTTP-GET request to inject arbitrary code or access sensitive files on the server.
Mitigation:
No fix has been published yet. A suggested workaround is to add code to the 'archiv.cgi' file that checks the file extension of the 'template' parameter and rejects non-HTML files. The vendor has been informed about the vulnerability.