CasecadeSoft W3Mail Attachment...

- AV AC AU C I A
发布: 2002-07-25
修订: 2025-04-13

A vulnerability has been reported in W3Mail that may result in the disclosure of user email attachments. When attachments are uploaded, they are stored in a directory within the webroot. There is no default index file created. If the webserver is configured to output the index of directories, remote clients may view and retrieve attachment files without authorization. Reportedly, versions of W3Mail prior to 1.0.3 do not properly delete these files when the webmail user logs off, widening the window of opportunity for an attacker.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息