5
CVSSv2

CVE-2005-1105

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote malicious users to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.

Vulnerable Product Search on Vulmon Subscribe to Product

sun javamail 1.3.2

Exploits

source: wwwsecurityfocuscom/bid/13141/info Sun JavaMail is prone to a directory traversal vulnerability This arises because the API fails to properly validate filenames in email attachments received by the applet This issue was reported to affect JavaMail 132, however, earlier versions may also be vulnerable Content-Disposition: ...