|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
csMailto.cgi contains a flaw that may allow a malicious user to access arbitrary files. The issue is triggered when hidden form field values are modified. It is possible that the flaw may allow execution of arbitrary commands on the system resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 2.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
csMailto
 |
1.0 |
|
|
|
|
|
|
|
Credit |
- Steve Gustin - stegus1
yahoo.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|