Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1015063 | Broken Link Patch Third Party Advisory VDB Entry Vendor Advisory |
http://securitytracker.com/id?1015063 | Broken Link Patch Third Party Advisory VDB Entry Vendor Advisory |
Configurations
History
21 Nov 2024, 00:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://securitytracker.com/id?1015063 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
26 Jan 2024, 19:01
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 | |
References | (SECTRACK) http://securitytracker.com/id?1015063 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
Information
Published : 2005-10-23 10:02
Updated : 2024-11-21 00:01
NVD link : CVE-2005-3288
Mitre link : CVE-2005-3288
CVE.ORG link : CVE-2005-3288
JSON object : View
Products Affected
rockliffe
- mailsite_express
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type