PT-1997-1092 · Webgais · Webgais
Published
1997-07-08
·
Updated
2008-09-09
·
CVE-1999-0196
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Webgais version 1.0
Description
The issue allows a remote user to access arbitrary files and execute arbitrary code via the
receiver parameter, specifically the $VAR receiver variable, in the websendmail component.Recommendations
For Webgais version 1.0, consider restricting access to the websendmail component or the
$VAR receiver variable to minimize the risk of exploitation until a patch is available. Avoid using the receiver parameter in the affected component until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webgais