Back to search
CVE-2018-8741
Published: Mar 17, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.openwall.com/lists/oss-security/2018/03/17/2
x_refsource_MISC
https://gist.github.com/hannob/3c4f86863c418930ad08853c1109364e
x_refsource_MISC
1040554
vdb-entry
x_refsource_SECTRACK
DSA-4168
vendor-advisory
x_refsource_DEBIAN
https://paste.pound-python.org/show/OjSLiFTxiBrTk63jqEUu/
x_refsource_MISC
[debian-lts-announce] 20180416 [SECURITY] [DLA 1344-1] squirrelmail security update
mailing-list
x_refsource_MLIST
FEDORA-2019-ad02f64a79
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-1a87523729
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now