vendor:
MDaemon
by:
SecurityFocus
7.5
CVSS
HIGH
Input Validation Vulnerability
20
CWE
Product Name: MDaemon
Affected Version From: MDaemon 5.0.2
Affected Version To: MDaemon 5.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:alt-n_technologies:mdaemon
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2002
WorldClient Input Validation Vulnerability
WorldClient is a web interface packaged with MDaemon, an email server for Microsoft Windows. An input validation vulnerability exists in WorldClient that allows for an attacker to delete an arbitrary file on the webserver that it resides on. The vulnerability is due to a lack of input validation on the supplied filename for an attachment delete operation.
Mitigation:
Input validation should be performed on all user-supplied data.