emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Emu_webmail | Emumail | 5.0 (including) | 5.0 (including) |