CVE-2002-1385
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2002-1385. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed.
Available Exploits
Related News
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
CVSS Scoring
CVSS Score
References
Advisory provided by GitHub Security Advisory Database. Published: April 30, 2022, Modified: April 30, 2022