CVE-2005-1902
Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE,…
Does this matter?
Lower severity and a low EPSS score (3.55%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 3.55% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- e-post corporation/spa-pro mail atsolomon
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/15573Patch, Vendor Advisory
- http://securitytracker.com/id?1014095
- http://www.osvdb.org/16989
- http://www.security.org.sg/vuln/spa-promail4.htmlExploit, Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0680
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20860
- http://secunia.com/advisories/15573Patch, Vendor Advisory
- http://securitytracker.com/id?1014095
- http://www.osvdb.org/16989
- http://www.security.org.sg/vuln/spa-promail4.htmlExploit, Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0680
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20860
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.