vendor:
Atmail
by:
SecurityFocus
7,5
CVSS
HIGH
Directory-Traversal, Arbitrary-File-Upload and Information-Disclosure
22, 264, 200
CWE
Product Name: Atmail
Affected Version From: Atmail 1.04
Affected Version To: Atmail 1.04
Patch Exists: YES
Related CWE: N/A
CPE: a:atmail:atmail
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
AtMail Multiple Directory-Traversal, Arbitrary-File-Upload and Information-Disclosure Vulnerabilities
AtMail is prone to multiple directory-traversal vulnerabilities, an arbitrary-file-upload vulnerability, and an information-disclosure vulnerability because the application fails to sanitize user-supplied input. An attacker can exploit these issues to obtain sensitive information, upload arbitrary code, and run it in the context of the webserver process.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized.