Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-8741

Опубликовано: 17 мар. 2018
Источник: debian
EPSS Низкий

Описание

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squirrelmailremovedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2018/03/17/2

  • https://sourceforge.net/p/squirrelmail/bugs/2846/

  • https://sourceforge.net/p/squirrelmail/code/14751/

EPSS

Процентиль: 82%
0.01736
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

CVSS3: 8.1
redhat
почти 8 лет назад

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

CVSS3: 8.8
nvd
почти 8 лет назад

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

CVSS3: 8.8
github
больше 3 лет назад

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

EPSS

Процентиль: 82%
0.01736
Низкий