9

CVE-2008-4932

Exploit
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter.  NOTE: this can be leveraged for code execution by writing to a file under the web document root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.52% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/32540
http://securityreason.com/securityalert/4565
http://www.securityfocus.com/archive/1/497961/100/0/threaded
http://www.securityfocus.com/bid/32013
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/46300
https://www.exploit-db.com/exploits/6898