Security Advisory
CVE-2015-9277
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.