7.2

CVE-2002-1385

openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for  openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open Webmail ≫ Open Webmail Version 1.7
Open Webmail ≫ Open Webmail Version 1.8
Open Webmail ≫ Open Webmail Version 1.71
Open Webmail ≫ Open Webmail Version 1.81
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.325
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=104031696120743&w=2
http://marc.info/?l=bugtraq&m=104032263328026&w=2
http://sourceforge.net/forum/forum.php?thread_id=782605&forum_id=108435
Patch
Vendor Advisory
http://www.securityfocus.com/bid/6425
https://exchange.xforce.ibmcloud.com/vulnerabilities/10904