CVE-2005-0332
Last modified
CVE-2005-0332 is a vulnerability of currently unknown severity. Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ventia | Desknow Mail And Collaboration Server | 2.5.12 |
| Ventia | Desknow Mail And Collaboration Server | 2.5.13 |
References
- http://www.security.org.sg/vuln/desknow2512.htmlVendor Advisory
- http://www.security.org.sg/vuln/desknow2512.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0332?
How severe is CVE-2005-0332?
How do I fix CVE-2005-0332?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0326pafiledb.php in PaFileDB 3.1 allows remote attackers to gain…
- CVE-2005-0327pafiledb.php in Pafiledb 3.1 may allow remote attackers to e…
- CVE-2005-0328Zyxel P310, P314, P324 and Netgear RT311, RT314 running the …
- CVE-2005-0329Directory traversal vulnerability in ZipGenius 5.5 and earli…
- CVE-2005-0330Buffer overflow in Painkiller 1.35 and earlier, and possibly…
- CVE-2005-0331Directory traversal vulnerability in WinRAR 3.42 and earlier…
- CVE-2005-0333LANChat Pro Revival 1.666c allows remote attackers to cause …
- CVE-2005-0334Linksys PSUS4 running firmware 6032 allows remote attackers …
- CVE-2005-0335Directory traversal vulnerability in EMotion MediaPartner We…
- CVE-2005-0336Cross-site scripting (XSS) vulnerability in EMotion MediaPar…
- CVE-2005-0337Postfix 2.1.3, when /proc/net/if_inet6 is not available and …
- CVE-2005-0338Buffer overflow in Savant Web Server 3.1 allows remote attac…
Are you affected by CVE-2005-0332?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
