MEDIUM
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL
Published Sep 17, 2010
5.0
MEDIUMCVSS 2.0
EPSS 8.36%
Description
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.
Affected products
No data.
AND
OR
- ≤ 7.4.1
- n/a
- 1.0.1
- 1.0.2
- 1.0.5
- 1.0.6
- 1.0.7
- 1.1.0
- 1.1.0
- 1.1.1
- 1.2.0
- 1.2.0
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.5
- 1.2.6
- 2.0
- 2.0.3
- 2.0.4
- 2.0.5
- 3.0
- 3.0
- 3.0.1
- 4.0
- 4.0
- 4.0.1
- 4.0.2
- 5.0
- 5.0
- 5.0.1
- 5.0.2
- 5.0.3
- 6.0.1
- 6.1
- 6.1
- 6.2
- 6.2.2
- 7.0
- 7.0
- 7.1
- 7.1.1
- 7.1.2
- 7.1.3
- 7.1.4
- 7.2
- 7.2
- 7.2.1
- 7.3
- 7.3
- 7.3.1
- 7.3.2
- 7.3.3
- 7.4
- 7.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://packetstormsecurity.org/1009-exploits/axigen741-traversal.txt x_refsource_MISCExploit
- http://secunia.com/advisories/41430 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.acunetix.com/blog/news/directory-traversal-axigen/ x_refsource_MISC
- http://www.axigen.com/press/product-releases/axigen-releases-version-742_74.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.osvdb.org/68027 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/43230 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2010/2415 vdb-entryx_refsource_VUPENPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-3458 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61826 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.org/1009-exploits/axigen741-traversal.txt | x_refsource_MISCExploit | |
| http://secunia.com/advisories/41430 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.acunetix.com/blog/news/directory-traversal-axigen/ | x_refsource_MISC | |
| http://www.axigen.com/press/product-releases/axigen-releases-version-742_74.html | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.osvdb.org/68027 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/43230 | vdb-entryx_refsource_BIDExploit | |
| http://www.vupen.com/english/advisories/2010/2415 | vdb-entryx_refsource_VUPENPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-3458 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/61826 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 17, 2010
Updated Aug 7, 2024
Reserved Sep 17, 2010
Link CVE-2010-3460
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-3458 Assigner mitre
Published Sep 17, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-3458