CVE-2005-0321: Low severity IceWarp Web Mail vulnerability
Published Feb 10, 2005
·Updated
MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendard.html, (2) calendarm.html, (3) calendarw.html, or (4) calendary.html, which reveal the installation path.
Affected Software
2 affected components
IceWarp Web Mail=5.3.0
Merak Mail Server=7.6.0
Event History
Feb 10, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0321?
CVE-2005-0321 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2005-0321?
To fix CVE-2005-0321, upgrade to a patched version of Merak Mail Server or IceWarp Web Mail that addresses this issue.
3
Who is affected by CVE-2005-0321?
CVE-2005-0321 affects users of Merak Mail Server version 7.6.0 and IceWarp Web Mail version 5.3.0.
4
What information is exposed by CVE-2005-0321?
CVE-2005-0321 allows remote authenticated users to gain access to sensitive installation path information.
5
Can CVE-2005-0321 be exploited remotely?
Yes, CVE-2005-0321 can be exploited remotely by authenticated users.