CVE-2008-4932

webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:comingchina:u-mail_webmail_server:4.91:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-11-05 15:00

Updated : 2024-02-04 17:33


NVD link : CVE-2008-4932

Mitre link : CVE-2008-4932

CVE.ORG link : CVE-2008-4932


JSON object : View

Products Affected

comingchina

  • u-mail_webmail_server
CWE
CWE-20

Improper Input Validation