Horde 1.2.x/2.1.3 and Imp 2.2.x/3.1.2 – File Disclosure

Horde 1.2.x/2.1.3 and Imp 2.2.x/3.1.2 – File Disclosure

漏洞ID 1053545 漏洞类型
发布时间 2001-07-13 更新时间 2001-07-13
图片[1]-Horde 1.2.x/2.1.3 and Imp 2.2.x/3.1.2 – File Disclosure-安全小百科CVE编号 N/A
图片[2]-Horde 1.2.x/2.1.3 and Imp 2.2.x/3.1.2 – File Disclosure-安全小百科CNNVD-ID N/A
漏洞平台 Linux CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/21019
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/3067/info

A vulnerability has been discovered in Horde Imp which may allow an attacker to access arbitrary system files. The issue occurs due to insufficient sanity checks on user-supplied URI parameters.

By specifying a malicious INBOX file in a request, the contents of the file may be disclosed to a remote attacker. All files would be accessed with the privileges of the user invoking Imp. 

http://vulnerableserver/horde/imp/mailbox.php?mailbox=/etc/passwd

相关推荐: Windows Media Player Internet Shortcut Execution Vulnerability

Windows Media Player Internet Shortcut Execution Vulnerability 漏洞ID 1103173 漏洞类型 Design Error 发布时间 2001-05-23 更新时间 2001-05-23 CVE编…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享