CVE-2002-2331

W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cascadesoft:w3mail:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cascadesoft:w3mail:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cascadesoft:w3mail:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cascadesoft:w3mail:1.0.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/284232 - () http://online.securityfocus.com/archive/1/284232 -
References () http://www.iss.net/security_center/static/9680.php - () http://www.iss.net/security_center/static/9680.php -
References () http://www.securityfocus.com/bid/5314 - () http://www.securityfocus.com/bid/5314 -

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:43


NVD link : CVE-2002-2331

Mitre link : CVE-2002-2331

CVE.ORG link : CVE-2002-2331


JSON object : View

Products Affected

cascadesoft

  • w3mail
CWE
CWE-16

Configuration