Back
CVE-2005-3430
Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.
Published: Nov 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| rockliffe | mailsite_express | * |
| rockliffe | mailsite_express | 6.1.20 |
GitHub Security Advisory GHSA-rhv5-wwvq-gqxr
Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote...
References (14)
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0578.html Patch
- http://marc.info/?l=bugtraq&m=113053680631151&w=2
- http://secunia.com/advisories/17240/ Vendor Advisory
- http://securitytracker.com/id?1015117
- http://www.security-assessment.com/Advisories/Rockliffe_Express_Webmail_Vulnerabilities.pdf Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15230
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22907
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0578.html Patch
- http://marc.info/?l=bugtraq&m=113053680631151&w=2
- http://secunia.com/advisories/17240/ Vendor Advisory
- http://securitytracker.com/id?1015117
- http://www.security-assessment.com/Advisories/Rockliffe_Express_Webmail_Vulnerabilities.pdf Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15230
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22907
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.76%
Top 24% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub