Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html | mailing list vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html | mailing list |
http://www.securityfocus.com/bid/1738 | exploit vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5326 | vdb entry |