peter bassill · operator
$ cve CVE-2005-0313 JSON

CVE-2005-0313 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.4% (pctl 88)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.39% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2005-01-27
Last modified2026-06-16

Affected (1)

VendorProduct
amax information technologiesmagic winmail server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD