Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mail_machine | Mail_machine | 3.980 (including) | 3.980 (including) |
Mail_machine | Mail_machine | 3.985 (including) | 3.985 (including) |
Mail_machine | Mail_machine | 3.987 (including) | 3.987 (including) |
Mail_machine | Mail_machine | 3.988 (including) | 3.988 (including) |
Mail_machine | Mail_machine | 3.989 (including) | 3.989 (including) |