CVE-2008-4932
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.
Date published : 2008-11-05
http://www.securityfocus.com/bid/32013
http://www.securityfocus.com/archive/1/497961/100/0/threaded
