Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2005-02-10T05:00:00

Updated: 2017-07-10T14:57:01

Reserved: 2005-02-10T00:00:00


Link: CVE-2005-0332

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2005-05-02T04:00:00.000

Modified: 2017-07-11T01:32:14.250


Link: CVE-2005-0332

JSON object: View

cve-icon Redhat Information

No data.