CVE Vulnerabilities

CVE-2007-3702

Published: Jul 11, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.

Affected Software

NameVendorStart VersionEnd Version
Mail_machineMail_machine3.980 (including)3.980 (including)
Mail_machineMail_machine3.985 (including)3.985 (including)
Mail_machineMail_machine3.987 (including)3.987 (including)
Mail_machineMail_machine3.988 (including)3.988 (including)
Mail_machineMail_machine3.989 (including)3.989 (including)

References