First published: Tue Oct 12 2004(Updated: )
viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp WebMail Server | =3.3.2 | |
IceWarp WebMail Server | =5.2.7 | |
IceWarp WebMail Server | =5.2.8 | |
IceWarp Merak Mail Server | =7.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1674 is classified as a critical vulnerability due to its potential for remote file deletion and manipulation.
To fix CVE-2004-1674, upgrade Merak Mail Server to version 7.4.6 or Icewarp Web Mail to the latest available version.
CVE-2004-1674 affects Merak Mail Server version 7.4.5 and Icewarp Web Mail versions 5.2.7, 5.2.8, and likely others.
Attackers can exploit CVE-2004-1674 to delete or move arbitrary files on the server, posing a significant security risk.
CVE-2004-1674 remains a threat if affected versions of the software are still in use without proper updates or patches.