CVE-2004-1715: Medium severity Clearswift MIMEsweeper for Web vulnerability
Published Aug 11, 2004
·Updated
Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.
Affected Software
2 affected components
Clearswift MIMEsweeper for Web=4.0
Clearswift MIMEsweeper for Web=5.0.1
Remediation
Patch Available
Event History
Aug 11, 2004
CVE Published
04:00 AM
Feb 26, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1715?
CVE-2004-1715 is categorized as a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2004-1715?
To fix CVE-2004-1715, upgrade MIMEsweeper for Web to version 5.0.4 or later, which addresses this vulnerability.
3
Who is affected by CVE-2004-1715?
CVE-2004-1715 affects users of Clearswift MIMEsweeper for Web versions 4.0 and 5.0.1.
4
What are the exploit techniques for CVE-2004-1715?
CVE-2004-1715 can be exploited using directory traversal sequences such as '..\' in the URL to access restricted files.
5
What types of files can be accessed through CVE-2004-1715?
An attacker exploiting CVE-2004-1715 may read arbitrary files on the server that the application has permissions to access.