CVE-2007-3171
Uebimiau Webmail - Information Disclosure via Smarty or Selected_Theme Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3171. PoCs published by Michal Majchrowicz.
AI-analyzed exploit summary The provided text describes multiple input-validation vulnerabilities in Uebimiau, including XSS and information disclosure, but does not contain executable exploit code. It references URLs demonstrating vulnerable parameters.
Description
Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages.
Exploits (1)
The provided text describes multiple input-validation vulnerabilities in Uebimiau, including XSS and information disclosure, but does not contain executable exploit code. It references URLs demonstrating vulnerable parameters.