CVE Vulnerabilities

CVE-2002-0410

Published: Jul 26, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

Affected Software

Name Vendor Start Version End Version
Aeromail Aeromail 1.02 (including) 1.02 (including)
Aeromail Aeromail 1.10 (including) 1.10 (including)
Aeromail Aeromail 1.20 (including) 1.20 (including)
Aeromail Aeromail 1.26 (including) 1.26 (including)
Aeromail Aeromail 1.30 (including) 1.30 (including)
Aeromail Aeromail 1.40 (including) 1.40 (including)

References