MEDIUM · 5.0

CVE-2003-1330

Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAI...

Vulnerability Description

Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftAll WindowsAll versions
Clearswift LimitedMailsweeper4.3.6_sp1

References

FAQ

What is CVE-2003-1330?

CVE-2003-1330 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAI...

How severe is CVE-2003-1330?

CVE-2003-1330 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-1330?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft All Windows, Clearswift Limited Mailsweeper.