CVE-2002-0418

Directory traversal vulnerability in the com.endymion.sake.servlet.mail.MailServlet servlet for Endymion SakeMail 1.0.36 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the param_name parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:endymion:sake_mail:1.0.20:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.21:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.22:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.23:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.24:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.26:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.27:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.28:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.29:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.30:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.31:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.33:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.34:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.35:*:*:*:*:*:*:*
cpe:2.3:a:endymion:sake_mail:1.0.36:*:*:*:*:*:*:*

History

No history.

Information

Published : 2002-08-12 04:00

Updated : 2024-02-28 10:24


NVD link : CVE-2002-0418

Mitre link : CVE-2002-0418

CVE.ORG link : CVE-2002-0418


JSON object : View

Products Affected

endymion

  • sake_mail