CVE-2012-1919: Code Injection
Published Mar 27, 2012
·Updated
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory traversal attacks and read arbitrary files via a %0A sequence followed by a .. (dot dot) in the file parameter.
Affected Software
1 affected component
Atmail AtMail Open<=1.04
Remediation
Patch Available
Event History
Mar 27, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1919?
CVE-2012-1919 is considered a medium severity vulnerability due to its potential for directory traversal attacks.
2
How do I fix CVE-2012-1919?
To fix CVE-2012-1919, upgrade to AtMail Open-Source version 1.05 or later.
3
What software is affected by CVE-2012-1919?
CVE-2012-1919 affects AtMail Open-Source versions prior to 1.05.
4
What type of attacks can be performed using CVE-2012-1919?
CVE-2012-1919 allows remote attackers to conduct directory traversal attacks and read arbitrary files.
5
Is CVE-2012-1919 specific to any version of AtMail?
Yes, CVE-2012-1919 specifically impacts versions of AtMail Open-Source up to and including 1.04.