CVE-2005-1423 describes a directory traversal vulnerability in the mail program of 602LAN SUITE 2004.0.05.0413. This flaw allows remote attackers to use ".." sequences in the A parameter to potentially cause a denial of service and determine the existence of arbitrary files on the system. With a CVSS score of 6.4, this vulnerability is of medium severity, requiring no authentication and having low attack complexity, leading to partial confidentiality and availability impacts. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an exploit is available on ExploitDB, though it has garnered no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2004.0.05.0413CPE matchmatch criteria | cpe:2.3:a:software602:602lan_suite:2004.0.05.0413:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.