Description
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.
Affected products
- cobalt / qube3.0 – 3.0
- cobalt / webmail2.0.1 – 2.0.1