PT-2008-1966 · Afterlogic+1 · Afterlogic Mailbee Webmail Pro+1
-=M.O.B=-
·
Publicado
2008-01-17
·
Atualizado
2022-11-02
·
CVE-2008-0333
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AfterLogic MailBee WebMail Pro version 4.1 for ASP.NET
Description
The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability in the download view attachment.aspx file. This is achieved by using a .. (dot dot) in the
temp filename parameter of the vulnerable API endpoint "download view attachment.aspx".Recommendations
For AfterLogic MailBee WebMail Pro version 4.1 for ASP.NET, consider restricting access to the
download view attachment.aspx endpoint until a patch is available, and avoid using the temp filename parameter with unvalidated input to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Asp.Net
Afterlogic Mailbee Webmail Pro