CVE Vulnerabilities

CVE-2004-1670

Published: Sep 10, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ….// (doubled dot dot) in the folderold or folder parameters to folders.html.

Affected Software

NameVendorStart VersionEnd Version
Web_mailIcewarp3.3.2 (including)3.3.2 (including)
Web_mailIcewarp5.2.7 (including)5.2.7 (including)
Web_mailIcewarp5.2.8 (including)5.2.8 (including)
Mail_serverMerak7.4.5 (including)7.4.5 (including)

References