Rockliffe MailSite Express Arbitrary File Upload Vulnerability
BID:15129
Info
Rockliffe MailSite Express Arbitrary File Upload Vulnerability
| Bugtraq ID: | 15129 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2005 12:00AM |
| Updated: | Oct 18 2005 12:00AM |
| Credit: | Soroush dalili of Grayhatz security group is credited with the discovery of this vulnerability. |
| Vulnerable: |
Rockliffe MailSite Express 6.1.20 |
| Not Vulnerable: | |
Discussion
Rockliffe MailSite Express Arbitrary File Upload Vulnerability
MailSite Express is prone to an arbitrary file upload vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
MailSite Express is prone to an arbitrary file upload vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Exploit / POC
Rockliffe MailSite Express Arbitrary File Upload Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Rockliffe MailSite Express Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Rockliffe MailSite Express Arbitrary File Upload Vulnerability
References:
References:
- MailSite Express Homepage (Rockliffe)
- MailSite product site (Rockliffe)