CVE-2004-2586: Medium severity SmarterTools SmarterMail vulnerability
Published Dec 31, 2004
·Updated
Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to read arbitrary files via the filename parameter.
Affected Software
2 affected components
SmarterTools SmarterMail=1.6.1511
SmarterTools SmarterMail=1.6.1529
Event History
Dec 31, 2004
CVE Published
05:00 AM
Nov 29, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2586?
CVE-2004-2586 is classified as a high severity vulnerability due to its potential to expose sensitive files.
2
How do I fix CVE-2004-2586?
To fix CVE-2004-2586, upgrade SmarterMail to a patched version that addresses this directory traversal vulnerability.
3
What software versions are affected by CVE-2004-2586?
CVE-2004-2586 affects SmarterMail versions 1.6.1511 and 1.6.1529.
4
What type of attack does CVE-2004-2586 facilitate?
CVE-2004-2586 facilitates a directory traversal attack, allowing unauthorized access to arbitrary files on the server.
5
What must an attacker know to exploit CVE-2004-2586?
An attacker must know the filenames of the files they wish to access to exploit CVE-2004-2586 successfully.