The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imail | Ipswitch | 5.0 (including) | 5.0 (including) |
Imail | Ipswitch | 6.0 (including) | 6.0 (including) |
Imail | Ipswitch | 6.1 (including) | 6.1 (including) |
Imail | Ipswitch | 6.2 (including) | 6.2 (including) |
Imail | Ipswitch | 6.3 (including) | 6.3 (including) |
Imail | Ipswitch | 6.4 (including) | 6.4 (including) |