vendor:
Uebimiau Web-Mail
by:
Eugene Minaev
N/A
CVSS
N/A
Remote File Reader
CWE
Product Name: Uebimiau Web-Mail
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Uebimiau Web-Mail Remote File Reader
The Uebimiau Web-Mail application is vulnerable to a remote file reader exploit. By manipulating the script parameters, an attacker can trick the script into thinking they are an authorized user and gain unauthorized access to sensitive files. This vulnerability can be exploited if the register_globals setting is enabled.
Mitigation:
Disable the register_globals setting in the PHP configuration or upgrade to a newer version of the Uebimiau Web-Mail application that addresses this vulnerability.