CVE-2006-0332

Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ecartis:ecartis:1.0.0_snapshot_2005-09-09:*:*:*:*:*:*:*

History

21 Nov 2024, 00:06

Type Values Removed Values Added
References () http://marc.info/?l=listar-dev&m=113732552708625&w=2 - () http://marc.info/?l=listar-dev&m=113732552708625&w=2 -
References () http://marc.info/?l=listar-dev&m=113770802408358&w=2 - () http://marc.info/?l=listar-dev&m=113770802408358&w=2 -
References () http://secunia.com/advisories/18524 - Patch, Vendor Advisory () http://secunia.com/advisories/18524 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/16317 - Patch () http://www.securityfocus.com/bid/16317 - Patch
References () http://www.vupen.com/english/advisories/2006/0260 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/0260 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24220 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24220 -

Information

Published : 2006-01-21 00:03

Updated : 2024-11-21 00:06


NVD link : CVE-2006-0332

Mitre link : CVE-2006-0332

CVE.ORG link : CVE-2006-0332


JSON object : View

Products Affected

ecartis

  • ecartis
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')