PT-2004-3350 · Open Webmail · Open Webmail

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2458

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Open WebMail versions 2.30 and earlier
Description: The issue allows remote attackers to create arbitrary directories before authentication, due to the creation of new directories when use syshomedir is disabled or create syshomedir is enabled.
Recommendations: For Open WebMail versions 2.30 and earlier, consider disabling the creation of new directories until a patch is available, or restrict access to directory creation functionality to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2458

Affected Products

Open Webmail