vendor:
U-Mail
by:
Shennan Wang
7.5
CVSS
HIGH
Input Validation Error
20
CWE
Product Name: U-Mail
Affected Version From: U-Mail 4.91
Affected Version To: U-Mail 4.91
Patch Exists: NO
Related CWE: N/A
CPE: a:comingchina:u-mail
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
U-Mail Webmail Arbitrary File Write Vulnerability
This vulnerability allows remote attackers to write arbitrary file on vulnerable installations of U-Mail Webmail Server. Authentication is required to exploit this vulnerability.The specific flaw exists in the 'edit.php' file running on the U-Mail Webmail Server. A malicious HTTP POST request can write arbitrary file to the publicly accessible web directories.
Mitigation:
Ensure that input is properly validated and sanitized before being used in a file write operation.