exploit-db-mirror/exploits/linux/remote/21019.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

7 lines
No EOL
504 B
Text

source: https://www.securityfocus.com/bid/3067/info
A vulnerability has been discovered in Horde Imp which may allow an attacker to access arbitrary system files. The issue occurs due to insufficient sanity checks on user-supplied URI parameters.
By specifying a malicious INBOX file in a request, the contents of the file may be disclosed to a remote attacker. All files would be accessed with the privileges of the user invoking Imp.
http://vulnerableserver/horde/imp/mailbox.php?mailbox=/etc/passwd