Description
Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.
Affected products
- clearswift / mailsweeper4.0 – 4.0
- clearswift / mailsweeper4.1 – 4.1
- clearswift / mailsweeper4.2 – 4.2
- clearswift / mailsweeper4.3 – 4.3
Exploits & proofs of concept
- exploit-dbClearswift MAILsweeper 4.x - MIME Attachment Filter Bypassby http-equiv
Updated 10m ago · 8 sources