search.results.php in HiveMail 3.1 and earlier allows remote attackers to obtain the installation path via certain manipulations related to the (1) searchdate and (2) folderids parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hivemail | Hivemail | * | 3.1 (including) |
Hivemail | Hivemail | 1.1 (including) | 1.1 (including) |
Hivemail | Hivemail | 1.1.1 (including) | 1.1.1 (including) |
Hivemail | Hivemail | 1.2 (including) | 1.2 (including) |
Hivemail | Hivemail | 1.2.1_beta1 (including) | 1.2.1_beta1 (including) |
Hivemail | Hivemail | 1.2.1_rc (including) | 1.2.1_rc (including) |
Hivemail | Hivemail | 1.2.2 (including) | 1.2.2 (including) |
Hivemail | Hivemail | 1.2_sp1 (including) | 1.2_sp1 (including) |
Hivemail | Hivemail | 1.3 (including) | 1.3 (including) |
Hivemail | Hivemail | 1.3_beta1 (including) | 1.3_beta1 (including) |
Hivemail | Hivemail | 1.3_rc1 (including) | 1.3_rc1 (including) |