CVE-2005-3430
Summary
| CVE | CVE-2005-3430 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-11-02 11:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rockliffe | Mailsite Express | 6.1.20 | All | All | All |
| Application | Rockliffe | Mailsite Express | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rockliffe MailSite Express Arbitrary Script File Upload Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Risks in POS Systems: The Importance of a Security Assessment | af854a3a-2127-422b-91ae-364da2661108 | www.security-assessment.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - RockLiffe MailSite Express WebMail Discloses WebMail Files to Remote Users and Permits Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| archives.neohapsis.com/archives/fulldisclosure/2005-10/0578.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Patch |
| 'Multiple vulnerabilities within RockLiffe MailSite Express WebMail' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Secunia - Advisories - MailSite Express Attachment Upload and Script Insertion | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.