CVE-2004-1720: Medium severity Merak Mail Server vulnerability
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1720?
CVE-2004-1720 has a medium severity due to potential exposure of sensitive information.
How do I fix CVE-2004-1720?
To fix CVE-2004-1720, update your Merak Mail Server to version 7.4.6 or later.
What software is affected by CVE-2004-1720?
CVE-2004-1720 affects Merak Mail Server version 5.2.7 and may affect higher versions up to 7.4.5.
What type of information does CVE-2004-1720 expose?
CVE-2004-1720 exposes the installation path of the Merak Mail Server through invalid HTTP requests.
Can CVE-2004-1720 be exploited remotely?
Yes, CVE-2004-1720 can be exploited remotely by attackers sending invalid HTTP requests.