{"api_version":"1","generated_at":"2026-07-23T08:14:04+00:00","cve":"CVE-2005-1902","urls":{"html":"https://cve.report/CVE-2005-1902","api":"https://cve.report/api/cve/CVE-2005-1902.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1902","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1902"},"summary":{"title":"CVE-2005-1902","description":"Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-06-09 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:N","baseScore":3.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1014095","name":"http://securitytracker.com/id?1014095","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SPA-PRO Mail @Solomon Input Validation Hole Discloses Files to Remote Users and Buffer Overflow Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/16989","name":"http://www.osvdb.org/16989","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/15573","name":"http://secunia.com/advisories/15573","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - SPA-PRO Mail @Solomon IMAP Directory Traversal and Buffer Overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20860","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20860","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/0680","name":"http://www.vupen.com/english/advisories/2005/0680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.security.org.sg/vuln/spa-promail4.html","name":"http://www.security.org.sg/vuln/spa-promail4.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"SIG^2 G-TEC - SPA-PRO Mail @Solomon IMAP Server Directory Traversal and Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1902","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1902","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1902","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"e-post_corporation","cpe5":"spa-pro_mail_atsolomon","cpe6":"4.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.524Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1014095","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014095"},{"name":"spa-pro-imap-diectory-traversal(20860)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20860"},{"name":"ADV-2005-0680","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/0680"},{"name":"15573","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15573"},{"name":"16989","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/16989"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.security.org.sg/vuln/spa-promail4.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-06-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1014095","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014095"},{"name":"spa-pro-imap-diectory-traversal(20860)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20860"},{"name":"ADV-2005-0680","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/0680"},{"name":"15573","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15573"},{"name":"16989","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/16989"},{"tags":["x_refsource_MISC"],"url":"http://www.security.org.sg/vuln/spa-promail4.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1902","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1014095","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014095"},{"name":"spa-pro-imap-diectory-traversal(20860)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20860"},{"name":"ADV-2005-0680","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/0680"},{"name":"15573","refsource":"SECUNIA","url":"http://secunia.com/advisories/15573"},{"name":"16989","refsource":"OSVDB","url":"http://www.osvdb.org/16989"},{"name":"http://www.security.org.sg/vuln/spa-promail4.html","refsource":"MISC","url":"http://www.security.org.sg/vuln/spa-promail4.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1902","datePublished":"2005-06-08T04:00:00.000Z","dateReserved":"2005-06-08T00:00:00.000Z","dateUpdated":"2024-08-07T22:06:57.524Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-06-09 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:N","baseScore":3.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:e-post_corporation:spa-pro_mail_atsolomon:4.00:*:*:*:*:*:*:*","matchCriteriaId":"DD8AF0E8-0447-40CF-B68F-D8BD59E2466E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1902","Ordinal":"1","Title":"CVE-2005-1902","CVE":"CVE-2005-1902","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1902","Ordinal":"1","NoteData":"Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands.","Type":"Description","Title":"CVE-2005-1902"},{"CveYear":"2005","CveId":"1902","Ordinal":"2","NoteData":"2005-06-08","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1902","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}