McAfee Email and Web Security Appliance / Email Gateway contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to read arbitrary files.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related,
Security Software
Solution
Upgrade Email and Web Security to version 5.5 Patch 6 or 5.6 Patch 3 or higher, and Email Gateway to version 7.0 Patch 1 or higher, as as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.