frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte (%00). NOTE: it is not clear whether this issue poses a vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smartermail | Smartertools | 1.6.1511 (including) | 1.6.1511 (including) |
Smartermail | Smartertools | 1.6.1529 (including) | 1.6.1529 (including) |