Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-10-23T04:00:00Z

Updated: 2024-09-17T01:52:03.870Z

Reserved: 2005-10-23T00:00:00Z

Link: CVE-2005-3288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-10-23T10:02:00.000

Modified: 2024-01-26T19:01:22.753

Link: CVE-2005-3288

cve-icon Redhat

No data.