Back

CVE-2005-3430

Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.

Published: Nov 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
rockliffe mailsite_express *
rockliffe mailsite_express 6.1.20

GitHub Security Advisory GHSA-rhv5-wwvq-gqxr

Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.76%

Top 24% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub