Mail Machine "archives" Parameter Processing Arbitrary File Download Vulnerability
Description
A vulnerability has been identified in Mail Machine, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "mailmachine.cgi" script that does not validate the "archives" parameter, which could be exploited by attackers to download arbitrary files from a vulnerable server.
Vulnerable Products
Vulnerable Software: Mail Machine version 3.989 and prior