CVE-2012-1919
27.03.2012, 19:55
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory traversal attacks and read arbitrary files via a %0A sequence followed by a .. (dot dot) in the file parameter.
Vendor | Product | Version |
---|---|---|
atmail | atmail_open | 𝑥 ≤ 1.04 |
𝑥
= Vulnerable software versions
References