CVE-2004-1671: Medium severity IceWarp Web Mail vulnerability
Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettingsadd.html or (2) topmenu.html.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1671?
CVE-2004-1671 is considered to be of medium severity due to the potential for sensitive information disclosure.
How do I fix CVE-2004-1671?
To fix CVE-2004-1671, update to the latest version of IceWarp Web Mail that addresses this vulnerability.
What versions are affected by CVE-2004-1671?
CVE-2004-1671 affects Merak Mail Server 7.4.5 with Icewarp Web Mail versions 5.2.7, 5.2.8, and 3.3.2.
What kind of information can be disclosed by CVE-2004-1671?
CVE-2004-1671 allows remote attackers to gain access to sensitive information through direct requests to specific web server files.
Is there a patch available for CVE-2004-1671?
Yes, a patch is available by updating IceWarp Web Mail to a version that resolves CVE-2004-1671.