Record summary

CVE-2010-3486 has a selected CVSS score of 5.0; EIP currently links 3 catalogued exploits.

Description

Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded backslash) in the name parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBSmarterMail 7.1.3876 - Directory TraversalExploitDB exploitby sqlhackerNot analyzed1 file
ExploitDB

PoC details
ExploitDBSmarterMail < 7.2.3925 - LDAP InjectionExploitDB exploitby sqlhackerNot analyzed1 file
ExploitDB

PoC details
ExploitDBSmarterMail 7.3/7.4 - Multiple VulnerabilitiesExploitDB exploitby Hoyt LLC ResearchNot analyzed1 file
ExploitDB

PoC details

References

6