CVE Vulnerabilities

CVE-2002-2331

Published: Dec 31, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments.

Affected Software

Name Vendor Start Version End Version
W3mail Cascadesoft 1.0.2 (including) 1.0.2 (including)
W3mail Cascadesoft 1.0.3 (including) 1.0.3 (including)
W3mail Cascadesoft 1.0.4 (including) 1.0.4 (including)
W3mail Cascadesoft 1.0.5 (including) 1.0.5 (including)

References