Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-4940 PoC — Axigen Free Mail Server ‘View Log Files’组件多个目录遍历漏洞

Source
Associated Vulnerability
Title:Axigen Free Mail Server ‘View Log Files’组件多个目录遍历漏洞 (CVE-2012-4940)
Description:Axigen Messaging Axigen Mail Server是罗马尼亚Axigen Messaging公司的一款小型的邮件服务器,它可与SMTP、IMAP和WebMail等服务相结合使用。 Axigen Free邮件服务器中的View Log Files组件中存在多个目录遍历漏洞。通过将..(点点)植入(1)下载操作中的fileName参数传送到source/loggin/page_log_dwn_file.hsp,或(2)编辑操作或(3)删除操作中的fileName参数传送到默认的URI,远程
Description
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in an edit or delete action to the default URI.
File Snapshot

id: CVE-2012-4940 info: name: Axigen Mail Server Filename Directory Traversal author: dhiyanesh ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.