Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-0332

Опубликовано: 02 мая 2005
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ventia:desknow_mail_and_collaboration_server:2.5.12:*:*:*:*:*:*:*
cpe:2.3:a:ventia:desknow_mail_and_collaboration_server:2.5.13:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01626
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.

EPSS

Процентиль: 82%
0.01626
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other