Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.
References
Configurations
History
21 Nov 2024, 00:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=listar-dev&m=113732552708625&w=2 - | |
References | () http://marc.info/?l=listar-dev&m=113770802408358&w=2 - | |
References | () http://secunia.com/advisories/18524 - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/16317 - Patch | |
References | () http://www.vupen.com/english/advisories/2006/0260 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/24220 - |
Information
Published : 2006-01-21 00:03
Updated : 2024-11-21 00:06
NVD link : CVE-2006-0332
Mitre link : CVE-2006-0332
CVE.ORG link : CVE-2006-0332
JSON object : View
Products Affected
ecartis
- ecartis
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')