CVE

Id
12863  
CVE No.
CVE-2005-1657  
Status
Candidate  
Description
Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5) Message.Command parameter to messages.ctml.  
Phase
Assigned (20050518)  
Votes
None (candidate not yet proposed)  
Comments