Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-2331

Опубликовано: 31 дек. 2002
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cascadesoft:w3mail:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cascadesoft:w3mail:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cascadesoft:w3mail:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cascadesoft:w3mail:1.0.5:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01555
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-16

Связанные уязвимости

github
больше 3 лет назад

W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments.

EPSS

Процентиль: 81%
0.01555
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-16