Описание
Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or delete directories via a .. (dot dot) in the argument to the (1) CREATE, (2) SELECT, (3) DELETE, or (4) RENAME commands.
Ссылки
- ExploitVendor Advisory
- Vendor Advisory
- Patch
- ExploitVendor Advisory
- Vendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 4.8.03.025 (включая)
cpe:2.3:a:macallan:mail_solution:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.01946
Низкий
5.5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or delete directories via a .. (dot dot) in the argument to the (1) CREATE, (2) SELECT, (3) DELETE, or (4) RENAME commands.
EPSS
Процентиль: 83%
0.01946
Низкий
5.5 Medium
CVSS2
Дефекты
NVD-CWE-Other