VYPR
Medium severity6.5NVD Advisory· Published Mar 15, 2018· Updated Jun 17, 2026

CVE-2018-7706

CVE-2018-7706

Description

Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a .. (dot dot) in the option2 parameter in an attachment action to secmail/getmessage.exe.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:securenvoy:securmail:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:securenvoy:securmail:*:*:*:*:*:*:*:*range: <9.2.501
    • (no CPE)range: <9.2.501

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.