Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2005-3430
Disclosure Date: November 02, 2005 (last updated February 22, 2025)
Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.
0
Attacker Value
Unknown
CVE-2005-3287
Disclosure Date: October 23, 2005 (last updated February 22, 2025)
Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which are not converted to .TXT like other dangerous extensions, and which can be directly requested from the cache directory.
0
Attacker Value
Unknown
CVE-2005-3288
Disclosure Date: October 23, 2005 (last updated February 22, 2025)
Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.
0
Attacker Value
Unknown
CVE-2000-0398
Disclosure Date: May 24, 2000 (last updated February 22, 2025)
Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.
0