CVE-2024-32399
HIGH NUCLEIRaidenMAILD Mail Server <4.9.4 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-32399. PoCs published by NN0b0dy. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a functional proof-of-concept for CVE-2024-32399, demonstrating a directory traversal vulnerability in RaidenMAILD Mail Server v4.9.4 and earlier. The PoC includes a crafted HTTP request to access sensitive files (e.g., win.ini) via the /webeditor/ component.
Description
Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.
Exploits (1)
The repository contains a functional proof-of-concept for CVE-2024-32399, demonstrating a directory traversal vulnerability in RaidenMAILD Mail Server v4.9.4 and earlier. The PoC includes a crafted HTTP request to access sensitive files (e.g., win.ini) via the /webeditor/ component.
Nuclei Templates (1)
html:"RaidenMAILD"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L