vendor:
V-Webmail
by:
beford
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: V-Webmail
Affected Version From: 1.3
Affected Version To: 1.6.4
Patch Exists: YES
Related CWE: N/A
CPE: a:v-webmail:v-webmail
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
V-Webmail 1.6.4
V-webmail is a powerful PHP based webmail application with an abundance of features, including many innovative ideas for web applications. The vulnerability exists in the v-webmail/includes/pear/*/*.php and v-webmail/includes/mailaccess/pop3.php files, which allow an attacker to include a remote file by manipulating the CONFIG[pear_dir] parameter. Versions 1.3, 1.5 and 1.6.4 are vulnerable.
Mitigation:
Upgrade to the latest version of V-Webmail.