VulnerabilityModified
CVE-2008-0464
Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a ..
MEDIUM 5.0EPSS 3.32%
Does this matter?
Lower severity and a low EPSS score (3.32%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.32% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- absofort/aconon mail enterprise sql
- Source
- cve@mitre.org
References
- http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059856.htmlExploit
- http://secunia.com/advisories/28617Vendor Advisory
- http://www.securityfocus.com/bid/27427Exploit
- http://www.vupen.com/english/advisories/2008/0310
- https://www.exploit-db.com/exploits/4977
- http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059856.htmlExploit
- http://secunia.com/advisories/28617Vendor Advisory
- http://www.securityfocus.com/bid/27427Exploit
- http://www.vupen.com/english/advisories/2008/0310
- https://www.exploit-db.com/exploits/4977
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.