5

CVE-2008-0333

Exploit
Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AfterlogicMailbee Webmail Pro Version4.1 SwPlatformasp.net
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.66% 0.955
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://secunia.com/advisories/28521
Not Applicable
http://www.securityfocus.com/bid/27312
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39724
Third Party Advisory
VDB Entry
https://www.exploit-db.com/exploits/4921
Third Party Advisory
Exploit
VDB Entry