First published: Sun Feb 06 2005(Updated: )
Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail Vacation Plugin | <=0.15 | |
SquirrelMail Vacation Plugin | <=0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0184 is classified as a medium severity vulnerability due to its ability to permit unauthorized file access.
To fix CVE-2005-0184, upgrade the SquirrelMail Vacation plugin to a version later than 0.15.
Users of SquirrelMail with the Vacation plugin version 0.15 or earlier are affected by CVE-2005-0184.
Local users can exploit CVE-2005-0184 to read arbitrary files by crafting a specific get request using directory traversal techniques.
Yes, CVE-2005-0184 can be easily exploited by inputting a simple dot dot sequence in the file path.