The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mail_server | Merak | 5.2.7 (including) | 5.2.7 (including) |