Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_mail | Icewarp | 5.4.2 (including) | 5.4.2 (including) |
Mail_server | Merak | 8.0.3 (including) | 8.0.3 (including) |