CVE-2015-9277: Path Traversal
Published Jan 16, 2019
·Updated
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
Affected Software
1 affected component
MailEnable MailEnable<8.60
Event History
Jan 16, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9277?
CVE-2015-9277 is considered a critical vulnerability due to its potential for unauthorized access and manipulation of user data.
2
How do I fix CVE-2015-9277?
To fix CVE-2015-9277, update MailEnable to version 8.60 or later to mitigate the directory traversal issue.
3
What types of attacks can exploit CVE-2015-9277?
CVE-2015-9277 can be exploited through directory traversal attacks, allowing unauthorized users to read, upload, or delete files.
4
Which versions of MailEnable are affected by CVE-2015-9277?
MailEnable versions before 8.60 are vulnerable to CVE-2015-9277.
5
What are the potential impacts of CVE-2015-9277?
The potential impacts of CVE-2015-9277 include data breaches, loss of user data, and unauthorized file access.