CVE-2018-5700: Magicwinmail Winmail Server
High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.
Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder into a web folder.
Affected products
- Magicwinmail Winmail Server: up to and including 6.2
Published 2018-01-14. Last modified 2026-06-17.