PT-2004-2624 · Icewarp · Merak Mail Server

Published

2004-08-17

·

Updated

2017-07-11

·

CVE-2004-1720

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Merak Mail Server version 5.2.7
Description The issue allows remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. This is possible through the address.html page and possibly the calendar.html page, although the latter's exposure is unclear as the path may be leaked in web logs only accessible to administrators.
Recommendations For Merak Mail Server version 5.2.7, consider restricting access to the address.html page and potentially the calendar.html page until a fix is available. As a temporary workaround, limit the information revealed in web logs to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1720

Affected Products

Merak Mail Server