WorldClient Arbitrary File Deletion Vulnerability
BID:4687
Info
WorldClient Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 4687 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2002 12:00AM |
| Updated: | May 07 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Obscure <[email protected]>. |
| Vulnerable: |
Deerfield Worldclient Pro 5.0 Deerfield Worldclient 5.0.5 Deerfield Worldclient 5.0.4 Deerfield Worldclient 5.0.3 Deerfield Worldclient 5.0.2 Deerfield Worldclient 5.0.1 Deerfield Worldclient 5.0 |
| Not Vulnerable: |
Deerfield Worldclient 5.0.6 |
Discussion
WorldClient Arbitrary File Deletion Vulnerability
WorldClient is a web interface packaged with MDaemon, an email server for Microsoft Windows.
An input validation vulnerability exists in WorldClient that allows for an attacker to delete an arbitrary file on the webserver that it resides on. The vulnerability is due to a lack of input validation on the supplied filename for an attachment delete operation.
WorldClient is a web interface packaged with MDaemon, an email server for Microsoft Windows.
An input validation vulnerability exists in WorldClient that allows for an attacker to delete an arbitrary file on the webserver that it resides on. The vulnerability is due to a lack of input validation on the supplied filename for an attachment delete operation.