First published: Wed Dec 28 2005(Updated: )
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clearswift MIMEsweeper for Web | =5.0.4 | |
Clearswift MIMEsweeper for Web | =5.1 | |
Clearswift MIMEsweeper for Web | =5.0.3 | |
Clearswift MIMEsweeper for Web | =5.0.5 | |
Clearswift MIMEsweeper for Web | =4.0 | |
Clearswift MIMEsweeper for Web | =5.0.2 | |
Clearswift MIMEsweeper for Web | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4526 is considered a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2005-4526, upgrade Clearswift MIMEsweeper For Web to a version that addresses this vulnerability.
CVE-2005-4526 affects Clearswift MIMEsweeper For Web versions 4.0 through 5.1.
Yes, CVE-2005-4526 can allow remote attackers to bypass filtering, potentially leading to the execution of malicious code.
CVE-2005-4526 allows the exploitation of executable files that do not have a .exe extension in their URLs.