CVE-2012-1918: Path Traversal
Published Mar 27, 2012
·Updated
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allow remote attackers to read arbitrary files via a .. (dot dot) in the Attachment[] parameter.
Affected Software
1 affected component
Atmail AtMail Open<=1.04
Remediation
Patch Available
Event History
Mar 27, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1918?
CVE-2012-1918 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.
2
How do I fix CVE-2012-1918?
To fix CVE-2012-1918, upgrade your AtMail Open-Source to version 1.05 or later.
3
What types of attacks can CVE-2012-1918 facilitate?
CVE-2012-1918 can facilitate directory traversal attacks, allowing attackers to read arbitrary files on the server.
4
Which versions of AtMail are affected by CVE-2012-1918?
CVE-2012-1918 affects AtMail Open-Source versions prior to 1.05.
5
What components of AtMail are vulnerable under CVE-2012-1918?
The vulnerable components identified in CVE-2012-1918 are compose.php and libs/Atmail/SendMsg.php.