5
CVSSv2

CVE-2005-1754

Published: 31/12/2005 Updated: 11/04/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

JavaMail API 1.1.3 up to and including 1.3, as used by Apache Tomcat 5.0.16, allows remote malicious users to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

Vulnerable Product Search on Vulmon Subscribe to Product

sun javamail 1.1.3

sun javamail 1.3

sun javamail 1.2

apache tomcat apache tomcat 5.0.16

sun javamail 1.3.2

Exploits

source: wwwsecurityfocuscom/bid/13753/info Sun JavaMail is prone to multiple information disclosure vulnerabilities The issues exist due to a lack of sufficient input sanitization performed on user-supplied requests The following issues are reported: A remote attacker may reveal the contents of email attachments of other users A remo ...