VYPR
High severity8.8NVD Advisory· Published Mar 17, 2018· Updated Jun 17, 2026

CVE-2018-8741

CVE-2018-8741

Description

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:squirrelmail:squirrelmail:1.4.22:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:squirrelmail:squirrelmail:1.4.22:*:*:*:*:*:*:*
    • (no CPE)range: =1.4.22
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.