First published: Fri Dec 31 2004(Updated: )
frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterMail Enterprise | =1.6.1511 | |
SmarterTools SmarterMail Enterprise | =1.6.1529 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-2584 is not clear, but it involves a potential issue with folder creation that could impact SmarterMail functionality.
To mitigate the issues posed by CVE-2004-2584, ensure that folder creation inputs are sanitized to prevent null byte injection.
CVE-2004-2584 affects users of SmarterTools SmarterMail versions 1.6.1511 and 1.6.1529.
CVE-2004-2584 allows remote authenticated users to create folders that cannot be deleted or renamed, possibly hindering management of email folders.
It is not fully clear whether CVE-2004-2584 poses a confirmed vulnerability as it lacks detailed exploitation evidence.