Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0140 (Webmail)

BugsAlert Home > CVE-2008-0140 (Webmail)
 
 

Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0140

Learn more about CVE-2008-0140 (Webmail)
 
Tags: cve-2008-0140 webmail

Related Items

      Sophos podcast reveals the latest security threats and trends

      MailMachinePRO "id" SQL Injection Vulnerability

      Mahara HTML File Upload Script Insertion Vulnerability

      FrSIRT - Opera Browser Code Execution and Security Bypass Vulnerabilities

      VBS_RUNAUTO.M

      Mandriva: Subject: [Security Announce] [ MDVSA-2008:222 ] Eterm

      Which is best

 

Pixel