EMUMail HTTP Host Arbitrary Config...

- AV AC AU C I A
发布: 2002-04-10
修订: 2025-04-13

Emumail is a web mail package available from Emumail, Inc. It is designed for use on Linux, Unix, and Windows systems. Under some circumstances, it is possible for a local user to gain privileges equal to the HTTP server process. Upon connecting to the server and supplying a malicious HTTP Host value to emumail, it could be possible to force the program to open an arbitrary file. This could addition result in the execution of an arbitrary program, supplied by an attacker with local access to the host.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息