Vulnerability CVE-2005-0332


Published: 2005-05-02   Modified: 2012-02-12

Description:
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Ventia -> Desknow mail and collaboration server 

 References:
http://xforce.iss.net/xforce/xfdb/19211
http://xforce.iss.net/xforce/xfdb/19206
http://www.securityfocus.com/bid/12421
http://xforce.iss.net/xforce/xfdb/19212
http://www.security.org.sg/vuln/desknow2512.html
http://securitytracker.com/id?1013060
http://secunia.com/advisories/14116
http://marc.theaimsgroup.com/?l=bugtraq&m=110737616324614&w=2

Copyright 2024, cxsecurity.com

 

Back to Top