CVE-2005-1657
Estado: ModificadaAlta (7.5)—
Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5) Message.Command parameter to messages.ctml.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.91%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/15234
- http://www.osvdb.org/16220
- http://www.osvdb.org/16221
- http://www.osvdb.org/16222
- http://www.osvdb.org/16223
- http://www.osvdb.org/16224
- http://www.osvdb.org/16225
- http://secunia.com/advisories/15234
- http://www.osvdb.org/16220
- http://www.osvdb.org/16221
- http://www.osvdb.org/16222
- http://www.osvdb.org/16223
- http://www.osvdb.org/16224
- http://www.osvdb.org/16225
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-1657",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-05-18T04:00:00.000",
"references": [
{
"url": "http://secunia.com/advisories/15234",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/16220",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/16221",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/16222",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/16223",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/16224",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/16225",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/15234",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/16220",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/16221",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/16222",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/16223",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/16224",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/16225",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5) Message.Command parameter to messages.ctml."
}
],
"lastModified": "2026-06-16T22:13:26.947",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mercur:mercur_messaging:2005_sp2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5599BD24-5F07-4495-9869-81A5A2F4988F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}