CVE-2002-2331 - CVE House
Back to Database
Status published Medium CVE-2002-2331

W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled...

Vulnerability Description

W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-2331

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

cascadesoft

View all reports →

Affected Software

w3mail
Vulnerable Versions:
1.0.2, 1.0.3, 1.0.4, 1.0.5

Timeline

Official Publish: October 26th, 2007
Last Modified: September 17th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.