Описание
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
Ссылки
- Product
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
EPSS
5.8 Medium
CVSS3
7.5 High
CVSS3
Дефекты
Связанные уязвимости
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthentic ...
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter.
EPSS
5.8 Medium
CVSS3
7.5 High
CVSS3