CVE-2018-7706: Path Traversal
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a .. (dot dot) in the option2 parameter in an attachment action to secmail/getmessage.exe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7706?
CVE-2018-7706 is classified as a medium severity vulnerability due to its ability to allow unauthorized access to arbitrary email messages.
How do I fix CVE-2018-7706?
To fix CVE-2018-7706, update your SecurEnvoy SecurMail software to version 9.2.501 or later.
What causes CVE-2018-7706?
CVE-2018-7706 is caused by a directory traversal vulnerability that allows remote authenticated users to access unauthorized files.
Who is affected by CVE-2018-7706?
CVE-2018-7706 affects users of SecurEnvoy SecurMail versions prior to 9.2.501.
Can CVE-2018-7706 lead to further exploitation?
Yes, CVE-2018-7706 can potentially lead to further exploitation if sensitive information is accessed by unauthorized users.