Clearswift MAILsweeper 4.x - MIME Attachment Filter Bypass
Author: http-equiv
type: remote
platform: windows
port: nan
date_added: 2003-03-07
date_updated: 2012-11-04
verified: 1
codes: CVE-2003-0121;OSVDB-8810
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/7044/info
Clearswift MailSweeper does not properly process certain malformed MIME email message attachments. If the attachment does not contain a MIME-Version field, MailSweeper does not recognize the attachment as being an executable type. MailSweeper allows such attachments through, even if it is set to filter executable type file attachments from incoming email messages.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/22338.zip