Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/4687 | exploit vdb entry patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9027 | vdb entry |
http://online.securityfocus.com/archive/1/271374 | mailing list |