A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.
References
Configurations
History
No history.
Information
Published : 2018-03-17 14:29
Updated : 2024-11-21 04:14
NVD link : CVE-2018-8741
Mitre link : CVE-2018-8741
CVE.ORG link : CVE-2018-8741
JSON object : View
Products Affected
squirrelmail
- squirrelmail
debian
- debian_linux
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')