← Back

CVE-2002-2331

nvd nist
Published: Dec 31, 2002Modified: Apr 16, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments.

Affected (4)

Products: Cascadesoft: W3mail
1 product
W3mail
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Cascadesoft
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5

Related CWEs

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.