CVE-2005-1489: Medium severity Merak Mail Server vulnerability
Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendaraddevent.html, (2) calendarevent.html, or (3) calendartask.html.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1489?
CVE-2005-1489 is classified as having a medium severity due to its potential for exposing sensitive system information.
How do I fix CVE-2005-1489?
To mitigate CVE-2005-1489, update to the latest version of Merak Mail Server and IceWarp Web Mail that addresses this vulnerability.
Who is affected by CVE-2005-1489?
CVE-2005-1489 impacts users of Merak Mail Server version 8.0.3 and IceWarp Web Mail version 5.4.2.
What types of information can be exposed by CVE-2005-1489?
CVE-2005-1489 could allow remote authenticated users to retrieve the full server path, potentially aiding in further attacks.
When was CVE-2005-1489 disclosed?
CVE-2005-1489 was disclosed in 2005, highlighting vulnerabilities in older versions of the Merak Mail Server and IceWarp Web Mail.