>> Aconon Mail "template" Parameter Directory Traversal Vulnerability
Title : Aconon Mail "template" Parameter Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2008-0310 CVE ID : CVE-2008-0464
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-29
Technical Description
A vulnerability has been identified in Aconon Mail 2004, which could be exploited by attackers to gain unauthorized read access to arbitrary files. This issue is caused by an input validation error in the "archiv.cgi" script that does not validate the "template" parameter, which could be exploited by malicious people to disclose the contents of arbitrary files on a vulnerable server via directory traversal attacks.