CVE-2018-8741
17.03.2018, 14:29
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.
Vendor | Product | Version |
---|---|---|
squirrelmail | squirrelmail | 1.4.22 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References