Description
Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.
Affected products
- alt-n / worldclient5.0 – 5.0
- alt-n / worldclient5.0 – 5.0
- alt-n / worldclient5.0.1 – 5.0.1
- alt-n / worldclient5.0.2 – 5.0.2
- alt-n / worldclient5.0.3 – 5.0.3
- alt-n / worldclient5.0.4 – 5.0.4
- alt-n / worldclient5.0.5 – 5.0.5