PT-2002-3043 · W3 · W3Mail

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2331

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions W3Mail versions 1.0.2 through 1.0.5
Description The issue allows remote attackers to execute arbitrary code by sending code in MIME attachments and then requesting the attachments, due to the failure to properly restrict the types of files that can be uploaded as attachments when server side scripting (SSI) is enabled in the attachments directory.
Recommendations For W3Mail versions 1.0.2 through 1.0.5, consider disabling server side scripting (SSI) in the attachments directory until a patch is available. Restrict access to the attachments directory to minimize the risk of exploitation. Avoid using the attachments feature with SSI enabled until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-2331

Produtos afetados

W3Mail