Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Stalkerlab's Mailers cgimail.exe可获取服务器任意文件漏洞
Vulnerability Description
Mailers是Stalker Lab的一个WEBMAIL产品,其中包含了一个叫cgimail.exe的程序,用于把用户提交表单的内容转换为一个email。 cgimail.exe实现上存在输入验证漏洞,远程攻击者可能利用此漏洞获得服务器上的任意文件。 该程序未对从表单中提交上来的变量$To$、$Attach$、$File$内容进行检查,导致攻击者可以把服务器上的任意有权限访问的文件以附件的形式发送给自己。
CVSS Information
N/A
Vulnerability Type
N/A