CVE-2005-3429
Summary
| CVE | CVE-2005-3429 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-11-02 11:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies via cross-site scripting (XSS) vulnerabilities. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rockliffe | Mailsite Express | 6.1.20 | All | All | All |
| Application | Rockliffe | Mailsite Express | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Risks in POS Systems: The Importance of a Security Assessment | af854a3a-2127-422b-91ae-364da2661108 | www.security-assessment.com | Exploit, Patch, Vendor Advisory |
| SecurityTracker.com Archives - RockLiffe MailSite Express WebMail Discloses WebMail Files to Remote Users and Permits Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| archives.neohapsis.com/archives/fulldisclosure/2005-10/0578.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit, Patch |
| 'Multiple vulnerabilities within RockLiffe MailSite Express WebMail' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| www.osvdb.org/22682 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.