Security Advisory

CVE-2018-7705

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-03-14 20:00:00
Last updated 2024-08-05 06:31:05
Assigner mitre
State PUBLISHED

Description

Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipients via a .. (dot dot) in the filename parameter to secupload2/upload.aspx.