Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-4932

EPSS 11.11% · P94
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-4932

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
U-Mail 'edit.php' 任意文件上传漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
U-Mail专家级邮件系统是福洽科技最新推出的第四代企业邮局系统。 U-Mail邮件系统的edit.php文件没有正确地处理HTTP POST参数,远程攻击者可以通过提交恶意请求向webroot下的任意文件写入数据。如果向带有.php扩展的文件写入了PHP代码的话,就可能导致执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-4932

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-4932

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-11-05 · 37 CVEs total

CVE-2008-4952Emacs和XEmacs Jabber 'emacs-jabber'任意文件重写漏洞
CVE-2008-4944Cdcontrol writtercontrol 任意文件重写漏洞
CVE-2008-4945tivano Amanda CDRW-Taper 任意文件重写漏洞
CVE-2008-4946xenman convirt 任意文件重写漏洞
CVE-2008-4947Debian DHIS-server 'dhis-dummy-log-engine' 任意文件重写漏洞
CVE-2008-4948nostatic digitaldj 'fest.pl' 任意文件重写漏洞
CVE-2008-4949manoj_srivastava dist 'metaconfig' 任意文件重写漏洞
CVE-2008-4950Debian dpkg-cross 任意文件重写漏洞
CVE-2008-4951Debian DTC-common 任意文件重写漏洞
CVE-2008-4943iglues bulmages-servers任意文件重写漏洞
CVE-2008-4953FireHOL 'firehol' 任意文件重写漏洞
CVE-2008-4954Debian fml ''libexec/mead.pl' 任意文件重写漏洞
CVE-2008-4955freevo 'freevo.real'任意文件重写漏洞
CVE-2008-4956firewall builder 'fwb_install'任意文件重写漏洞
CVE-2008-4957Kitware GCC-XML 'find_flags'任意文件重写漏洞
CVE-2008-4958alejandro_garrido_mota 'gdrae' 任意文件重写漏洞
CVE-2008-4959GpsDrive 'geo-code'任意文件重写漏洞
CVE-2008-4960impose+ 任意文件重写漏洞
CVE-2008-4934Linux Kernel 'bitmap.c' hfsplus_block_allocate()函数本地拒绝服务漏洞
CVE-2008-4812Adobe Acrobat和Reader Type 1字体越界数组索引漏洞

Showing top 20 of 37 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-4932

No comments yet


Leave a comment