Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-1710

Опубликовано: 31 дек. 2002
Источник: nvd
CVSS2: 3.6
EPSS Низкий

Описание

The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:basilix:basilix_webmail:1.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.0007
Низкий

3.6 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.

EPSS

Процентиль: 21%
0.0007
Низкий

3.6 Low

CVSS2

Дефекты

NVD-CWE-Other