HomeOpen WebmailCVE-2002-1385

CVE-2002-1385

UNKNOWN
7.2CVSS
Published: 2002-12-26
Updated: 2025-04-03
AI Analysis

Description

openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed.

CVSS Metrics

Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector
local
Access Cmplx
low
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
OPEN_WEBMAIL
Published
12/26/2002
Last Modified
4/3/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

open_webmail : open_webmailopen_webmail : open_webmailopen_webmail : open_webmailopen_webmail : open_webmail

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief