Description
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action or (3) a delete action to the default URI.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T20:50:18.304Z
Reserved: 2012-09-17T00:00:00.000Z
Link: CVE-2012-4940
No data.
Status : Deferred
Published: 2012-10-31T19:55:00.983
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-4940
No data.
OpenCVE Enrichment
No data.
Weaknesses