CVE-2012-4940
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a ..
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 83.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action or (3) a delete action to the default URI.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 83.63% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- gecad/axigen free mail server
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/586556US Government Resource
- http://www.securityfocus.com/bid/56343
- http://www.kb.cert.org/vuls/id/586556US Government Resource
- http://www.securityfocus.com/bid/56343
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.