Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Basilix_webmail | Basilix | 1.02_beta (including) | 1.02_beta (including) |
Basilix_webmail | Basilix | 1.03_beta (including) | 1.03_beta (including) |