PT-2004-2576 · Icewarp · Merak Mail Server

Shineshadow

·

Published

2004-09-10

·

Updated

2017-07-11

·

CVE-2004-1670

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Merak Mail Server version 7.4.5
Description The issue allows remote attackers to create arbitrary directories or rename arbitrary files. This can be achieved by exploiting directory traversal vulnerabilities, specifically by using a .. (dot dot) in the user parameter to viewaction.html or a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.
Recommendations For Merak Mail Server version 7.4.5, consider restricting access to the viewaction.html and folders.html endpoints until a patch is available. As a temporary workaround, avoid using the user, folderold, and folder parameters in the affected API endpoints.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1670

Affected Products

Merak Mail Server