First published: Fri Sep 10 2004(Updated: )
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Merak Mail Server | =7.4.5 | |
IceWarp Web Mail | =5.2.7 | |
IceWarp Web Mail | =5.2.8 | |
IceWarp Web Mail | =3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.