First published: Tue Oct 12 2004(Updated: )
accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp WebMail Server | =5.2.7 | |
IceWarp WebMail Server | =5.2.8 | |
IceWarp WebMail Server | =3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1673 is considered a high-severity vulnerability due to its potential for unauthorized file creation.
To fix CVE-2004-1673, update the IceWarp Web Mail Server to the latest patched version to ensure the vulnerability is mitigated.
CVE-2004-1673 affects IceWarp Web Mail versions 5.2.7, 5.2.8, and 3.3.2.
CVE-2004-1673 allows remote attackers to exploit the vulnerability via the accountid parameter to create text files with arbitrary content.
Yes, CVE-2004-1673 is exploitable remotely over the network by sending crafted requests to the vulnerable server.