PT-2004-2576 · Icewarp · Merak Mail Server

Shineshadow

·

Publicado

2004-09-10

·

Atualizado

2017-07-11

·

CVE-2004-1670

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Merak Mail Server version 7.4.5
Description The issue allows remote attackers to create arbitrary directories or rename arbitrary files. This can be achieved by exploiting directory traversal vulnerabilities, specifically by using a .. (dot dot) in the user parameter to viewaction.html or a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.
Recommendations For Merak Mail Server version 7.4.5, consider restricting access to the viewaction.html and folders.html endpoints until a patch is available. As a temporary workaround, avoid using the user, folderold, and folder parameters in the affected API endpoints.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1670

Produtos afetados

Merak Mail Server