PT-2008-2096 · Absofort Aconon · Absofort Aconon Mail 2004 Enterprise Sql+1

Arno Toll

·

Published

2008-01-25

·

Updated

2017-09-29

·

CVE-2008-0464

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions absofort aconon Mail 2007 Enterprise SQL version 11.7.0 absofort aconon Mail 2004 Enterprise SQL version 11.5.1
Description A directory traversal issue exists in the archiv.cgi component, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the template parameter.
Recommendations For absofort aconon Mail 2007 Enterprise SQL version 11.7.0, restrict access to the archiv.cgi component until a fix is available. For absofort aconon Mail 2004 Enterprise SQL version 11.5.1, avoid using the template parameter in the archiv.cgi component until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0464

Affected Products

Absofort Aconon Mail 2004 Enterprise Sql
Absofort Aconon Mail 2007 Enterprise Sql