Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter.
Link | Tags |
---|---|
http://mailreader.com/download/ChangeLog | |
http://www.iss.net/security_center/static/10490.php | vdb entry patch vendor advisory |
http://www.securityfocus.com/bid/6055 | exploit vdb entry patch vendor advisory |
http://www.debian.org/security/2004/dsa-534 | patch vendor advisory |
http://www.securityfocus.com/archive/1/297428 | mailing list exploit patch vendor advisory |