CVE-2012-4940 Information
Feb 14, 2021
cve
Description
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp or the fileName parameter in (2) an edit action or (3) a delete action to the default URI.
Reference
http://www.kb.cert.org/vuls/id/586556 http://www.securityfocus.com/bid/56343
Share on: