S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jun 13, 2024

CVE-2024-34470 Scanner

CVE-2024-34470 scanner - Local File Inclusion (LFI) vulnerability in HSC Mailinspector

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-34470
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Mailinspectorby hsc
*
Updated Aug 22, 2026View on NVD →
Detail

HSC Mailinspector is used by organizations for email monitoring and inspection to prevent spam and malware. It's commonly deployed by IT departments to enhance email security protocols. Mailinspector integrates with various email systems to filter and analyze incoming and outgoing mail traffic. It is designed for businesses of all sizes, from small enterprises to large corporations. The software ensures compliance with email policies and protects against email-based threats.

The vulnerability allows an unauthenticated attacker to exploit a path traversal flaw in the /public/loader.php file. This can lead to local file inclusion, allowing attackers to read arbitrary files on the server. The path parameter in the affected endpoint does not properly sanitize input, leading to this exposure. Successful exploitation can result in unauthorized access to sensitive files.

The Local File Inclusion vulnerability in HSC Mailinspector exists due to improper input filtering in the /public/loader.php file. The vulnerable endpoint is the path parameter, which fails to restrict access to files within the webroot. Attackers can manipulate this parameter to include files from the server's file system, such as /etc/passwd. This can be exploited by sending a crafted request to the vulnerable endpoint. The flaw is identified by detecting the presence of sensitive content, such as the root user entry, in the server's response.

If exploited, this vulnerability allows attackers to read arbitrary files on the server, potentially accessing sensitive information. This could include configuration files, user credentials, and other critical data. Unauthorized file access could lead to further exploitation of the system, escalating privileges, or compromising other parts of the network. The exposure of sensitive files can have severe security implications, including data breaches and loss of confidentiality.

Join the S4E platform to ensure comprehensive protection for your digital assets. Our platform provides advanced threat detection and exposure management to keep your systems secure. By becoming a member, you gain access to cutting-edge security checks, detailed vulnerability reports, and expert recommendations. Stay ahead of potential threats and safeguard your infrastructure with our proactive security solutions. Enhance your cybersecurity posture with the trusted services from S4E.

References:

Solution Advice
  • Update HSC Mailinspector to a version where this vulnerability is patched.
  • Implement input validation to sanitize and restrict file paths within the application.
  • Use web application firewalls (WAF) to detect and block suspicious requests.
  • Restrict access to sensitive files and directories on the server.
  • Regularly review and audit your web applications for similar vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.