CVE-2008-5991

MailWatch <1.0.4 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the doc parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by dun · textwebappsphp
https://www.exploit-db.com/exploits/6552

Scores

EPSS 0.0172
EPSS Percentile 82.2%

Classification

CWE
CWE-22
Status draft

Affected Products (8)

mailwatch/mailwatch < 1.0.4
mailwatch/mailwatch
mailwatch/mailwatch
mailwatch/mailwatch
mailwatch/mailwatch
mailwatch/mailwatch
mailwatch/mailwatch
mailwatch/mailwatch

Timeline

Published Jan 28, 2009
Tracked Since Feb 18, 2026