7.5

CVE-2005-0332

Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2% 0.782
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=110737616324614&w=2
http://secunia.com/advisories/14116
http://securitytracker.com/id?1013060
http://www.security.org.sg/vuln/desknow2512.html
Vendor Advisory
http://www.securityfocus.com/bid/12421
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/19206
https://exchange.xforce.ibmcloud.com/vulnerabilities/19211
https://exchange.xforce.ibmcloud.com/vulnerabilities/19212