PT-2004-2624 · Icewarp · Merak Mail Server
Published
2004-08-17
·
Updated
2017-07-11
·
CVE-2004-1720
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Merak Mail Server version 5.2.7
Description
The issue allows remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. This is possible through the address.html page and possibly the calendar.html page, although the latter's exposure is unclear as the path may be leaked in web logs only accessible to administrators.
Recommendations
For Merak Mail Server version 5.2.7, consider restricting access to the address.html page and potentially the calendar.html page until a fix is available. As a temporary workaround, limit the information revealed in web logs to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Merak Mail Server