CVE-2005-0313

Magic Winmail Server 4.0 Build 1112 - Directory Traversal and Arbitrary File Upload via upload.php and download.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-0313. PoCs published by Tan Chew Keong.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Magic Winmail Server's Webmail interface, allowing arbitrary file uploads. The PoC uploads a PHP file with a reverse shell payload to a traversed directory path.

Description

Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Tan Chew Keong · textwebappsphp
https://www.exploit-db.com/exploits/25065

This exploit demonstrates a directory traversal vulnerability in Magic Winmail Server's Webmail interface, allowing arbitrary file uploads. The PoC uploads a PHP file with a reverse shell payload to a traversed directory path.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Magic Winmail Server 4.0 (Build 1112)
No auth needed
Prerequisites: Network access to the target server · Webmail interface exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Tan Chew Keong · textwebappsphp
https://www.exploit-db.com/exploits/25064

This exploit demonstrates directory traversal vulnerabilities in Magic Winmail Server's Webmail interface, allowing arbitrary file downloads via crafted URLs. The PoC includes base64-encoded and plaintext traversal sequences to access sensitive files like 'userauth.cfg'.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Magic Winmail Server 4.0 (Build 1112)
Auth required
Prerequisites: Valid session ID (sid) · Access to the Webmail interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19114
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12388
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013017
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110685011825461&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14053
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19108

Scores

EPSS 0.0341
EPSS Percentile 87.3%

Details

Status published
Products (1)
amax_information_technologies/magic_winmail_server 4.0
Published Jan 27, 2005
Tracked Since Feb 18, 2026