Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FILE identifier with double-url-encoded ../ sequences (%252e%252e/).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ironmail | Ciphertrust | * | 6.1.1 (including) |
Ironmail | Ciphertrust | 4.1 (including) | 4.1 (including) |
Ironmail | Ciphertrust | 4.5.1 (including) | 4.5.1 (including) |
Ironmail | Ciphertrust | 5.0.1 (including) | 5.0.1 (including) |