CVE-2005-0332
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2005
Last modified:
03/04/2025
Description
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ventia:desknow_mail_and_collaboration_server:2.5.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ventia:desknow_mail_and_collaboration_server:2.5.13:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=110737616324614&w=2
- http://secunia.com/advisories/14116
- http://securitytracker.com/id?1013060=
- http://www.security.org.sg/vuln/desknow2512.html
- http://www.securityfocus.com/bid/12421
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19206
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19211
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19212
- http://marc.info/?l=bugtraq&m=110737616324614&w=2
- http://secunia.com/advisories/14116
- http://securitytracker.com/id?1013060=
- http://www.security.org.sg/vuln/desknow2512.html
- http://www.securityfocus.com/bid/12421
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19206
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19211
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19212



