CVE Vulnerabilities

CVE-2002-0410

Published: Jul 26, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

Affected Software

NameVendorStart VersionEnd Version
AeromailAeromail1.02 (including)1.02 (including)
AeromailAeromail1.10 (including)1.10 (including)
AeromailAeromail1.20 (including)1.20 (including)
AeromailAeromail1.26 (including)1.26 (including)
AeromailAeromail1.30 (including)1.30 (including)
AeromailAeromail1.40 (including)1.40 (including)

References