Vulnerabilities > CVE-2005-1105 - Unspecified vulnerability in SUN Javamail 1.3.2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
sun
exploit available

Summary

Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.

Vulnerable Configurations

Part Description Count
Application
Sun
1

Exploit-Db

descriptionSun JavaMail 1.3.2 MimeBodyPart.getFileName Directory Traversal Vulnerability. CVE-2005-1105. Remote exploits for multiple platform
idEDB-ID:25395
last seen2016-02-03
modified2005-04-12
published2005-04-12
reporterRafael San Miguel Carrasco
sourcehttps://www.exploit-db.com/download/25395/
titleSun JavaMail 1.3.2 MimeBodyPart.getFileName Directory Traversal Vulnerability