CVE-2004-1672: High severity IceWarp Web Mail vulnerability
attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the username and message ID in an HTTP request.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1672?
CVE-2004-1672 is considered to have a high severity due to its potential for unauthorized access to users' attachments.
How do I fix CVE-2004-1672?
To fix CVE-2004-1672, it is recommended to upgrade to the latest version of IceWarp Web Mail that addresses this vulnerability.
What systems are affected by CVE-2004-1672?
CVE-2004-1672 affects Merak Mail Server 7.4.5 with Icewarp Web Mail versions 5.2.7 and 5.2.8, as well as older versions such as 3.3.2.
What kind of attack does CVE-2004-1672 enable?
CVE-2004-1672 enables remote attackers to view any user's attachments by manipulating the username and message ID in HTTP requests.
Is user data at risk due to CVE-2004-1672?
Yes, CVE-2004-1672 poses a risk to user data as it allows unauthorized users to access sensitive attachments.