CVE-2018-18703: Path Traversal
PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow an attacker to read sensitive files on the system via directory traversal, bypassing the login page, as demonstrated by the Mailserverfilesystem/home.php coninb, consent, contrsh, condrft, or conspam parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18703?
CVE-2018-18703 is rated as high severity due to its potential for arbitrary file read, allowing attackers to access sensitive information.
How do I fix CVE-2018-18703?
To mitigate CVE-2018-18703, update PhpTpoint Mailing Server Using File Handling to the latest version that addresses the vulnerability.
What systems are affected by CVE-2018-18703?
CVE-2018-18703 affects PhpTpoint Mailing Server Using File Handling version 1.0.
What types of attacks can exploit CVE-2018-18703?
CVE-2018-18703 can be exploited through directory traversal attacks that allow unauthorized file access.
Are there any known exploits for CVE-2018-18703?
Yes, specific methods exist to exploit CVE-2018-18703 to read sensitive system files.