Unrated severityNVD Advisory· Published Jul 26, 2002· Updated Jun 16, 2026
CVE-2002-0410
CVE-2002-0410
Description
send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.
Affected products
7cpe:2.3:a:aeromail:aeromail:1.02:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:aeromail:aeromail:1.02:*:*:*:*:*:*:*
- cpe:2.3:a:aeromail:aeromail:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:aeromail:aeromail:1.20:*:*:*:*:*:*:*
- cpe:2.3:a:aeromail:aeromail:1.26:*:*:*:*:*:*:*
- cpe:2.3:a:aeromail:aeromail:1.30:*:*:*:*:*:*:*
- cpe:2.3:a:aeromail:aeromail:1.40:*:*:*:*:*:*:*
- (no CPE)range: <1.45
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.iss.net/security_center/static/8345.phpnvdPatchVendor Advisory
- www.securityfocus.com/bid/4214nvdPatchVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2002-03/0004.htmlnvdExploitVendor Advisory
- the.cushman.net/projects/aeromail/download/nvd
- the.cushman.net/projects/aeromail/download/aeromail-1.45.tar.gznvd
News mentions
0No linked articles in our index yet.