CVE-2004-1670: High severity Merak Mail Server vulnerability
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1670?
CVE-2004-1670 is classified as a high-severity vulnerability due to its potential for directory traversal attacks.
How do I fix CVE-2004-1670?
To fix CVE-2004-1670, upgrade to the latest version of Merak Mail Server or IceWarp Web Mail that addresses this vulnerability.
What versions are affected by CVE-2004-1670?
CVE-2004-1670 affects Merak Mail Server version 7.4.5 and IceWarp Web Mail versions 3.3.2, 5.2.7, and 5.2.8.
What types of attacks can be performed using CVE-2004-1670?
CVE-2004-1670 allows remote attackers to create arbitrary directories and rename files through directory traversal exploitation.
Is CVE-2004-1670 still a concern for current systems?
While CVE-2004-1670 was reported in 2004, systems using affected versions are still at risk if not updated or patched.