← Back to CVE List

CVE-2019-12938

Published: 2019-06-24T14:15Z
Last Modified: 2024-11-21T04:23Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with the Apache HTTP Server but is ineffective with nginx. Attackers can read logs via the webmail/logs/sendmail URI. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt