Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter.
| Software | From | Fixed in |
|---|---|---|
| emumail / emumail_unix | 5.0 | 5.0.x |
| emumail / emumail_red_hat_linux | 5.0 | 5.0.x |
| emumail / emumail_red_hat_linux | 5.1 | 5.1.x |
| emumail / emumail_unix | 5.1 | 5.1.x |
| emumail / emumail | 3.0 | 3.0.x |