Exploitation Summary
EIP tracks 1 public exploit for CVE-1999-0842. PoCs published by Ussr Labs.
AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in Mail-Gear's webserver, allowing remote attackers to read arbitrary files on the filesystem by manipulating the URL path. The example provided demonstrates accessing the 'autoexec.bat' file on a default NT installation.
Description
Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.
Exploits (1)
The exploit describes a directory traversal vulnerability in Mail-Gear's webserver, allowing remote attackers to read arbitrary files on the filesystem by manipulating the URL path. The example provided demonstrates accessing the 'autoexec.bat' file on a default NT installation.