CVE-2005-0332
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- ventia/desknow mail and collaboration server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110737616324614&w=2
- http://secunia.com/advisories/14116
- http://securitytracker.com/id?1013060
- http://www.security.org.sg/vuln/desknow2512.htmlVendor Advisory
- http://www.securityfocus.com/bid/12421Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19206
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19211
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19212
- http://marc.info/?l=bugtraq&m=110737616324614&w=2
- http://secunia.com/advisories/14116
- http://securitytracker.com/id?1013060
- http://www.security.org.sg/vuln/desknow2512.htmlVendor Advisory
- http://www.securityfocus.com/bid/12421Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19206
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19211
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19212
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.