Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which are not converted to .TXT like other dangerous extensions, and which can be directly requested from the cache directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mailsite Express 不完整黑名单漏洞
Vulnerability Description
Mailsite Express是一款基于web的邮件客户端软件。 Mailsite Express存在不完整黑名单漏洞。 远程攻击者可以借助带有ASPX等可执行扩展名的附件,上传并可能执行文件。该扩展名如同其他危险扩展名一样不会转换为.TXT,并可从缓存目录直接请求。
CVSS Information
N/A
Vulnerability Type
N/A