CVE

Id
11538  
CVE No.
CVE-2005-0332  
Status
Candidate  
Description
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.  
Phase
Assigned (20050210)  
Votes
None (candidate not yet proposed)  
Comments