mlmmj Edit and Save Multiple Directory Traversal Vulnerabilities
BID:41080
Info
mlmmj Edit and Save Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 41080 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2010 12:00AM |
| Updated: | Jun 23 2010 12:00AM |
| Credit: | Florian Streib |
| Vulnerable: |
mlmmj mlmmj 1.2.16 mlmmj mlmmj 1.2.15 |
| Not Vulnerable: | |
Discussion
mlmmj Edit and Save Multiple Directory Traversal Vulnerabilities
mlmmj (Mailing List Managing Mad Joyful) is prone to multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to delete or overwrite arbitrary files within the context of the webserver.
mlmmj 1.2.15 and 1.2.16 are vulnerable; other versions may also be affected.
mlmmj (Mailing List Managing Mad Joyful) is prone to multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to delete or overwrite arbitrary files within the context of the webserver.
mlmmj 1.2.15 and 1.2.16 are vulnerable; other versions may also be affected.
Exploit / POC
mlmmj Edit and Save Multiple Directory Traversal Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
mlmmj Edit and Save Multiple Directory Traversal Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
mlmmj Edit and Save Multiple Directory Traversal Vulnerabilities
References:
References:
- Bug 607256 - mlmmj: Directory traversal flaw by editing and saving list entries (Jan Lieskovsky)
- Bugzilla Bug 259968 (Gentoo)
- CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entr (Jan iankko Lieskovs)
- mlmmj Homepage (mlmmj)