The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Msr45_isherlock-user | Hgiga | * | 4.5-117 (excluding) |
Ssr45_isherlock-user | Hgiga | * | 4.5-117 (excluding) |