CVE-2002-2331
Summary
| CVE | CVE-2002-2331 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cascadesoft | W3mail | 1.0.2 | All | All | All |
| Application | Cascadesoft | W3mail | 1.0.3 | All | All | All |
| Application | Cascadesoft | W3mail | 1.0.4 | All | All | All |
| Application | Cascadesoft | W3mail | 1.0.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CasecadeSoft W3Mail Attachment Exposure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ISS X-Force Database: w3mail-mime-attachment-execution (9680): W3Mail MIME attachment known location could allow an attacker to execute code | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| online.securityfocus.com/archive/1/284232 | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.