CVE-2002-1741
WorldClient for Alt-N Technologies MDaemon 5.0.5.0 - Directory Traversal via Attachments Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1741. PoCs published by Obscure.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file deletion vulnerability in WorldClient due to insufficient input validation in the attachment delete operation. The HTTP request manipulates the 'Attachments' parameter to traverse directories and delete a file outside the intended directory.
Description
Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.
Exploits (1)
This exploit demonstrates an arbitrary file deletion vulnerability in WorldClient due to insufficient input validation in the attachment delete operation. The HTTP request manipulates the 'Attachments' parameter to traverse directories and delete a file outside the intended directory.