CVE-2007-3702
Mail Machine 3.989 - Directory Traversal via Archives Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3702. PoCs published by H4 / XPK.
AI-analyzed exploit summary This exploit targets a local file inclusion vulnerability in Mail Machine versions 3.980 to 3.989. It sends a crafted HTTP POST request to read arbitrary files via path traversal in the 'archives' parameter.
Description
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.
Exploits (1)
This exploit targets a local file inclusion vulnerability in Mail Machine versions 3.980 to 3.989. It sends a crafted HTTP POST request to read arbitrary files via path traversal in the 'archives' parameter.