VulnerabilityModified
CVE-2010-3460
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.
MEDIUM 5.0EPSS 8.36%
Does this matter?
Lower severity and a low EPSS score (8.36%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 8.36% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- gecad/axigen mail server
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1009-exploits/axigen741-traversal.txtExploit
- http://secunia.com/advisories/41430Vendor Advisory
- http://www.acunetix.com/blog/news/directory-traversal-axigen/
- http://www.axigen.com/press/product-releases/axigen-releases-version-742_74.htmlPatch, Vendor Advisory
- http://www.osvdb.org/68027
- http://www.securityfocus.com/bid/43230Exploit
- http://www.vupen.com/english/advisories/2010/2415Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61826
- http://packetstormsecurity.org/1009-exploits/axigen741-traversal.txtExploit
- http://secunia.com/advisories/41430Vendor Advisory
- http://www.acunetix.com/blog/news/directory-traversal-axigen/
- http://www.axigen.com/press/product-releases/axigen-releases-version-742_74.htmlPatch, Vendor Advisory
- http://www.osvdb.org/68027
- http://www.securityfocus.com/bid/43230Exploit
- http://www.vupen.com/english/advisories/2010/2415Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61826
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.