PT-2005-2628 · Woppoware · Woppoware Postmaster

Published

2005-05-18

·

Updated

2008-09-05

·

CVE-2005-1651

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Woppoware PostMaster version 4.2.2 (build 3.2.5)
Description A directory traversal issue exists in the message.htm file, allowing remote attackers to determine the existence of arbitrary files by using a .. (dot dot) in the wmm parameter.
Recommendations For Woppoware PostMaster version 4.2.2 (build 3.2.5), consider restricting access to the wmm parameter in the message.htm file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1651

Affected Products

Woppoware Postmaster