The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
Link | Tags |
---|---|
http://packetstormsecurity.nl/0408-exploits/merak527.txt | patch vendor advisory |
http://www.osvdb.org/9045 | vdb entry patch vendor advisory |
http://www.securityfocus.com/bid/10966 | vdb entry patch vendor advisory |
http://securitytracker.com/id?1010969 | vdb entry |
http://marc.info/?l=bugtraq&m=109279057326044&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17029 | vdb entry |
http://secunia.com/advisories/12269 | third party advisory patch vendor advisory |