First published: Tue Oct 12 2004(Updated: )
Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Web Mail | =5.2.7 | |
IceWarp Web Mail | =5.2.8 | |
IceWarp Web Mail | =3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1671 is considered to be of medium severity due to the potential for sensitive information disclosure.
To fix CVE-2004-1671, update to the latest version of IceWarp Web Mail that addresses this vulnerability.
CVE-2004-1671 affects Merak Mail Server 7.4.5 with Icewarp Web Mail versions 5.2.7, 5.2.8, and 3.3.2.
CVE-2004-1671 allows remote attackers to gain access to sensitive information through direct requests to specific web server files.
Yes, a patch is available by updating IceWarp Web Mail to a version that resolves CVE-2004-1671.