PT-2004-2624 · Icewarp · Merak Mail Server

Publicado

2004-08-17

·

Atualizado

2017-07-11

·

CVE-2004-1720

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Merak Mail Server version 5.2.7
Description The issue allows remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. This is possible through the address.html page and possibly the calendar.html page, although the latter's exposure is unclear as the path may be leaked in web logs only accessible to administrators.
Recommendations For Merak Mail Server version 5.2.7, consider restricting access to the address.html page and potentially the calendar.html page until a fix is available. As a temporary workaround, limit the information revealed in web logs to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1720

Produtos afetados

Merak Mail Server